Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.888exploits catalogados
35.200CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC48
Proof of calc for CVE-2019-6453
CVE-2019-645318 feb 2019
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a
35RIESGO
abrir
GitHub PoC
Easy RM to MP3 Converter es un software que sufre de una vulnerabiliad de desbordamiento de buffer basada en la pila o StackBufferOverflow lo cual puede permite a los atacantes remotos ejecutar código arbitrario a través de un nombre de archivo largo en un archivo de lista de reproducción (.pls)
CVE-2009-133018 feb 2019
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir
GitHub PoC316
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
CVE-2019-100300015 feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
GitHub PoC7
getshell test
CVE-2019-573615 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC14
runc容器逃逸漏洞预警
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC1
likekabin/CVE-2019-5736
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
likekabin/cve-2019-5736-poc
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC6
Payload Generator
CVE-2019-7304HIGH14 feb 2019
Local privilege escalation via snapd socket
53RIESGO
abrir
GitHub PoC658
PoC for CVE-2019-5736
CVE-2019-573613 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC69
exploit for CVE-2018-4193
CVE-2018-419313 feb 2019
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RIESGO
abrir
GitHub PoC210
Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)
CVE-2019-573612 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC681
Linux privilege escalation exploit via snapd (CVE-2019-7304)
CVE-2019-7304HIGH12 feb 2019
Local privilege escalation via snapd socket
53RIESGO
abrir
GitHub PoC
Takes advantage of CVE-2018-10933
CVE-2018-10933CRITICAL10 feb 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC67
Programa ideal para robar toda la información de un dispositivo remotamente a través de la aplicación AirDroid. [CVE-2019-9599] (https://www.exploit-db.com/exploits/46337)
CVE-2019-959909 feb 2019
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RIESGO
abrir
GitHub PoC5
VMware NSX SD-WAN command injection vulnerability
CVE-2018-6961HIGHbajo ataque08 feb 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
GitHub PoC
cve-2018-15877
CVE-2018-1587708 feb 2019
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
GitHub PoC5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027704 feb 2019
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
GitHub PoC
cve-2018-3811
CVE-2018-381102 feb 2019
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RIESGO
abrir
GitHub PoC
cve-2018-3810
CVE-2018-381002 feb 2019
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
GitHub PoC16
iOS 12.0 -> 12.1.2 Incomplete Osiris Jailbreak with CVE-2019-6225 by GeoSn0w (FCE365)
CVE-2019-622531 ene 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RIESGO
abrir
GitHub PoC1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
CVE-2019-1653HIGHbajo ataque30 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
CVE-2011-355629 ene 2019
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir
GitHub PoC
Exploit script for Crossfire 1.9.0
CVE-2006-123629 ene 2019
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RIESGO
abrir
GitHub PoC2
DVR username password recovery.
CVE-2018-999528 ene 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC370
CVE-2018-8581
CVE-2018-8581HIGHbajo ataqueransomware24 ene 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir
GitHub PoC228
CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
CVE-2019-1652HIGHbajo ataque24 ene 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
GitHub PoC1
This is a exp of CVE-2018-15473
CVE-2018-15473MEDIUM23 ene 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
CVE-2017-1699522 ene 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC1
cve-2018-15961
CVE-2018-15961CRITICALbajo ataque21 ene 2019
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
GitHub PoC
CVE-2015-2794 auto finder
CVE-2015-279420 ene 2019
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir
anteriorpágina 430 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.