Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
CVE-2019-1742420 oct 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RIESGO
abrir
GitHub PoC
CVE-2019-17080
CVE-2019-1708018 oct 2019
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RIESGO
abrir
GitHub PoC9
Metasploit module & Python script for CVE-2019-16405
CVE-2019-1640518 oct 2019
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RIESGO
abrir
GitHub PoC89
kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque18 oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC3
Sudo Security Bypass (CVE-2019-14287)
CVE-2019-1428718 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC3
CVE 2019-2215 Android Binder Use After Free
CVE-2019-2215HIGHbajo ataque17 oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC6
Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results
CVE-2020-793417 oct 2019
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RIESGO
abrir
GitHub PoC
CVE-2012-5960, CVE-2012-5959 Proof of Concept
CVE-2012-596017 oct 2019
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir
GitHub PoC17
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
CVE-2019-1193216 oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
CVE-2019-1193216 oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
gurneesh/CVE-2019-14287-write-up
CVE-2019-1428716 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Exploit and Mass Pwn3r for CVE-2019-16920
CVE-2019-16920CRITICALbajo ataque16 oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RIESGO
abrir
GitHub PoC10
Standalone Python 3 exploit for CVE-2017-17562
CVE-2017-17562HIGHbajo ataque16 oct 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC9
CVE-2019-16728 Proof of Concept
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC3
CVE-2019-16278Nostromo httpd命令执行
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC70
Directory transversal to remote code execution
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC13
Sudo exploit
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
FauxFaux/sudo-cve-2019-14287
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC12
CVE-2018-13379 Script for Nmap NSE.
CVE-2018-13379CRITICALbajo ataqueransomware14 oct 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC134
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHbajo ataque14 oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
Spring Security OAuth 2.3 Open Redirection 分析复现篇
CVE-2019-377814 oct 2019
Open Redirect in spring-security-oauth2
28RIESGO
abrir
GitHub PoC
h-wookie/cve-2019-5736-poc
CVE-2019-573612 oct 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC4
Interactive-Like Command-Line Console for CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque12 oct 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
CVE-2018-7600CRITICALbajo ataqueransomware10 oct 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC16
Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.
CVE-2018-11776HIGHbajo ataque10 oct 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC10
PoC materials to exploit CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware10 oct 2019
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
GitHub PoC2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
CVE-2019-1712409 oct 2019
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RIESGO
abrir
GitHub PoC2
The study of vulnerability CVE-2017-3066. Java deserialization
CVE-2017-3066CRITICALbajo ataque09 oct 2019
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
CVE-2018-11776HIGHbajo ataque08 oct 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
anteriorpágina 414 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.