Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RIESGO
abrir
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALbajo ataque23 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
tafamace/CVE-2017-17485
CVE-2017-17485CRITICAL19 nov 2018
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RIESGO
abrir
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir
GitHub PoC83
Tool for CVE-2018-16323
CVE-2018-1632318 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RIESGO
abrir
GitHub PoC
cve-2018-14667 demo
CVE-2018-14667CRITICALbajo ataque18 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC3
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-1650917 nov 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC
Implementation of CVE-2018-10933 with CIDR block scanner
CVE-2018-10933CRITICAL16 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
My first try to code my own LPE exploit.
CVE-2017-1117613 nov 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
GitHub PoC9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
CVE-2016-4657HIGHbajo ataque11 nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
CVE-2009-409210 nov 2018
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RIESGO
abrir
GitHub PoC5
CMS Made Simple 2.2.7 RCE exploit
CVE-2018-1051709 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RIESGO
abrir
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHbajo ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
matlink/CVE-2018-17456
CVE-2018-1745608 nov 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
GitHub PoC14
Exploit for PlaySMS 1.4 authenticated RCE
CVE-2017-910106 nov 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir
GitHub PoC21
an RCE (remote command execution) approach of CVE-2018-7750
CVE-2018-775006 nov 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RIESGO
abrir
GitHub PoC
bolonobolo/CVE-2018-14665
CVE-2018-1466502 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
GitHub PoC2
matlink/CVE-2018-17961
CVE-2018-1796101 nov 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
GitHub PoC80
CVE-2018-8440 standalone exploit
CVE-2018-8440HIGHbajo ataqueransomware31 oct 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir
GitHub PoC2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
CVE-2018-15473MEDIUM31 oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
matlink/evince-cve-2017-1000083
CVE-2017-100008330 oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
CVE-2017-100008330 oct 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
GitHub PoC10
CVE-2018-2628漏洞工具包
CVE-2018-2628CRITICALbajo ataque30 oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC1
kastellanos/CVE-2018-7602
CVE-2018-7602CRITICALbajo ataqueransomware29 oct 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
GitHub PoC4
Exploit for vulnerability CVE-2018-6389 on wordpress sites
CVE-2018-638928 oct 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
anteriorpágina 434 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.