Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC105
CVE-2019-11580 Atlassian Crowd and Crowd Data Center RCE
CVE-2019-11580CRITICALbajo ataqueransomware17 jul 2019
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RIESGO
abrir
GitHub PoC92
Atlassian JIRA Template injection vulnerability RCE
CVE-2019-11581CRITICALbajo ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir
GitHub PoC
Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application CVE-2019-13063
CVE-2019-1306315 jul 2019
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RIESGO
abrir
GitHub PoC1
CVE-2019-9766 React
CVE-2019-976614 jul 2019
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RIESGO
abrir
GitHub PoC23
Metasploit module for massive Denial of Service using #Bluekeep vector.
CVE-2019-0708CRITICALbajo ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC4
R/W
CVE-2019-053912 jul 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
GitHub PoC14
thepwnrip/leHACK-Analysis-of-CVE-2018-8453
CVE-2018-8453HIGHbajo ataqueransomware08 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC4
PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.
CVE-2012-1823CRITICALbajo ataque05 jul 2019
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC4
PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.
CVE-2007-244705 jul 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC12
ze0r/CVE-2019-0708-exp
CVE-2019-0708CRITICALbajo ataqueransomware04 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
https://github.com/Yt1g3r/CVE-2019-3396_EXP.git
CVE-2019-3396CRITICALbajo ataqueransomware01 jul 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
Proof of concept code for breaking out of docker via runC
CVE-2019-573630 jun 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC3
TrungNguyen1909/CVE-2019-6225-macOS
CVE-2019-622530 jun 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RIESGO
abrir
GitHub PoC9
CVE-2019-10149 privilege escalation
CVE-2019-10149CRITICALbajo ataque27 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC99
cve-2019-0604 SharePoint RCE exploit
CVE-2019-0604CRITICALbajo ataqueransomware26 jun 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC1
spectre v4 : Speculative Store Bypass (CVE-2018-3639) proof of concept for Linux
CVE-2018-3639MEDIUM26 jun 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC
CVE-2017-8759 微软word漏洞利用脚本
CVE-2017-8759HIGHbajo ataque25 jun 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC14
POC CVE-2019-0708 with python script!
CVE-2019-0708CRITICALbajo ataqueransomware24 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Spins up an isolated test environment for experimentation with Apache Struts vulnerability CVE-2018-11776.
CVE-2018-11776HIGHbajo ataque24 jun 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC70
Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行
CVE-2019-2725HIGHbajo ataqueransomware24 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC9
CVE-2015-3337 ElasticSearch 任意文件读取
CVE-2015-333721 jun 2019
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a
50RIESGO
abrir
GitHub PoC5
CVE-2018-17456漏洞复现(PoC+Exp)
CVE-2018-1745621 jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
GitHub PoC3
CVE-2017-1000117漏洞复现(PoC+Exp)
CVE-2017-100011720 jun 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC1
wdfcc/CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware20 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
OpenSSH 用户名枚举漏洞(CVE-2018-15473)
CVE-2018-15473MEDIUM19 jun 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
oldthree3/CVE-2019-12735-VIM-NEOVIM
CVE-2019-1273518 jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
GitHub PoC1
MrAli-Code/CVE-2018-9995_dvr_credentials
CVE-2018-999516 jun 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC11
CVE-2019-2725 bypass pocscan and exp
CVE-2019-2725HIGHbajo ataqueransomware16 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC1
CVE-2019-1064 - AppXSVC Local Privilege Escalation
CVE-2019-1064HIGHbajo ataqueransomware16 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC35
weblogic绕过和wls远程执行
CVE-2019-2725HIGHbajo ataqueransomware15 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
anteriorpágina 421 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.