Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.973 exploits
GitHub PoC122
rce exploit , made to work with pocsuite3
CVE-2019-0708CRITICALbajo ataqueransomware17 ago 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
used to generate a valid attack chain to exploit CVE-2017-11774 tied to iranian apt only reasearch poc dont use for harm please
CVE-2017-11774HIGHbajo ataque16 ago 2019
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary command
83RIESGO
abrir
GitHub PoC27
Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF
CVE-2019-9670CRITICALbajo ataque16 ago 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
GitHub PoC1
Zimbra RCE CVE-2019-9670
CVE-2019-9670CRITICALbajo ataque16 ago 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
GitHub PoC5
Scan a list of given IP's for CVE-2017-12542
CVE-2017-1254216 ago 2019
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
GitHub PoC
Simple Python script for D-Link vulnerability scan and test [CVE-2019-13101]
CVE-2019-1310115 ago 2019
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RIESGO
abrir
GitHub PoC
Demo app of THAT data broker's security breach
CVE-2017-5638CRITICALbajo ataqueransomware15 ago 2019
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
major203/cve-2019-1181
CVE-2019-1181CRITICAL14 ago 2019
Remote Desktop Services Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC5
CVE-2017-11882(通杀Office 2003到2016)
CVE-2017-11882HIGHbajo ataqueransomware14 ago 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC1
CVE-2017-16995 ubuntun本地提权 POC
CVE-2017-1699514 ago 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC7
Linux 本地提权漏洞
CVE-2016-5195HIGHbajo ataque13 ago 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
OpenEMR security issue
CVE-2019-1453013 ago 2019
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can
50RIESGO
abrir
GitHub PoC65
Apache Solr远程代码执行漏洞(CVE-2019-0193) Exploit
CVE-2019-0193HIGHbajo ataque12 ago 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RIESGO
abrir
GitHub PoC253
CVE-2018-13379
CVE-2018-13379CRITICALbajo ataqueransomware11 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC146
CVE-2018-13382
CVE-2018-13382CRITICALbajo ataqueransomware11 ago 2019
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
GitHub PoC
ThanHuuTuan/CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque09 ago 2019
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC90
Apache Solr DataImport Handler RCE
CVE-2019-0193HIGHbajo ataque09 ago 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RIESGO
abrir
GitHub PoC4
linux 提权
CVE-2019-13272HIGHbajo ataque07 ago 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC
Lee-SungYoung/cve-2019-5736-study
CVE-2019-573605 ago 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.
CVE-2014-0160HIGHbajo ataque05 ago 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
CVE-2018-16509 Docker Playground - Ghostscript command execution
CVE-2018-1650904 ago 2019
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC1
提权漏洞
CVE-2019-13272HIGHbajo ataque04 ago 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC3
this is not stable
CVE-2013-202803 ago 2019
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
GitHub PoC1
SSH account enumeration verification script(CVE-2018-15473)
CVE-2018-15473MEDIUM02 ago 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC3
CVE-2019-1132
CVE-2019-1132HIGHbajo ataque31 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir
GitHub PoC5
The exploit for CVE-2019-13272
CVE-2019-13272HIGHbajo ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC332
Linux 4.10 < 5.1.17 PTRACE_TRACEME local root
CVE-2019-13272HIGHbajo ataque31 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC1
quandqn/cve-2018-14667
CVE-2018-14667CRITICALbajo ataque29 jul 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC4
infiniteLoopers/CVE-2019-2107
CVE-2019-210727 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir
GitHub PoC60
EoP POC for CVE-2019-1132
CVE-2019-1132HIGHbajo ataque26 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir
anteriorpágina 418 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.