Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC
Exploit SLmail Buffer Overflow CVE-2003-0264
CVE-2003-026416 sep 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2017-10271HIGHbajo ataqueransomware13 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC1
porting CVE-2016-7255 to x86 for educational purposes.
CVE-2016-7255HIGHbajo ataque13 sep 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
GitHub PoC513
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2019-2725HIGHbajo ataqueransomware13 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC1
veloCloud VMWare - Vulnerability
CVE-2018-6961HIGHbajo ataque12 sep 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
GitHub PoC7
C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]
CVE-2018-14847CRITICALbajo ataque11 sep 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC2
Simple poc of CVE-2018-8353 Microsoft Scripting Engine Use After Free
CVE-2018-835310 sep 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
GitHub PoC
likekabin/CVE-2018-8174-msf
CVE-2018-8174HIGHbajo ataqueransomware06 sep 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
jezzus/CVE-2018-11776-Python-PoC
CVE-2018-11776HIGHbajo ataque06 sep 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC
jezzus/CVE-2018-4121
CVE-2018-412106 sep 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir
GitHub PoC5
A remote code execution exploit for WebLogic based on CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque04 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware04 sep 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALbajo ataque03 sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 sep 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RIESGO
abrir
GitHub PoC13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
CVE-2018-638930 ago 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
CVE-2018-11776HIGHbajo ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
GitHub PoC16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC3
tuxotron/cve-2018-11776-docker
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHbajo ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC12
Vulnerable docker container for CVE-2018-11776
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC303
An exploit for Apache Struts CVE-2018-11776
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC3
moayadalmalat/CVE-2017-12636
CVE-2017-1263625 ago 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
GitHub PoC10
CVE-2018-11776(S2-057) EXPLOIT CODE
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
CVE-2018-8414HIGHbajo ataque24 ago 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RIESGO
abrir
GitHub PoC15
Creating a vulnerable environment and the PoC
CVE-2018-11776HIGHbajo ataque23 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC3
dangokyo/CVE-2015-5119
CVE-2015-5119HIGHbajo ataque21 ago 2018
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
GitHub PoC534
Exploit written in Python for CVE-2018-15473 with threading and export formats
CVE-2018-15473MEDIUM21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
anteriorpágina 439 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.