Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC534
Exploit written in Python for CVE-2018-15473 with threading and export formats
CVE-2018-15473MEDIUM21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
CVE-2018-095221 ago 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir
GitHub PoC3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
CVE-2018-15473MEDIUM19 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
CVE-2018-15473MEDIUM17 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC1
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHbajo ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC258
PoC for CVE-2018-15133 (Laravel unserialize vulnerability)
CVE-2018-15133HIGHbajo ataque14 ago 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
kaisaryousuf/CVE-2018-8208
CVE-2018-820813 ago 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
GitHub PoC118
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).
CVE-2018-889708 ago 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
GitHub PoC178
Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018
CVE-2018-4233HIGH08 ago 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir
GitHub PoC6
Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap
CVE-2018-994804 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
GitHub PoC96
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
CVE-2017-9248CRITICALbajo ataque03 ago 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC61
CVE-2007-2447 - Samba usermap script
CVE-2007-244703 ago 2018
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC2
Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules
CVE-2016-563901 ago 2018
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RIESGO
abrir
GitHub PoC20
on Mac 10.12.2
CVE-2017-237030 jul 2018
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
GitHub PoC7
A demo exploit of CVE-2016-9079 on Ubuntu x64
CVE-2016-9079HIGHbajo ataque29 jul 2018
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
GitHub PoC
PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow
CVE-2004-227125 jul 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir
GitHub PoC8
CVE-2013-6117
CVE-2013-611723 jul 2018
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
GitHub PoC2
This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).
CVE-2010-360020 jul 2018
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir
GitHub PoC
likekabin/CVE-2018-4121
CVE-2018-412117 jul 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir
GitHub PoC
likekabin/ShareDoc_cve-2015-5477
CVE-2015-547717 jul 2018
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC49
Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)
CVE-2018-1378416 jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir
GitHub PoC
happynote3966/CVE-2018-7602
CVE-2018-7602CRITICALbajo ataqueransomware12 jul 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
GitHub PoC
Linux Null pointer dereference
CVE-2009-269212 jul 2018
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RIESGO
abrir
GitHub PoC
happynote3966/CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware12 jul 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
happynote3966/CVE-2014-3704
CVE-2014-370411 jul 2018
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
GitHub PoC1
dd
CVE-2018-8120HIGHbajo ataqueransomware11 jul 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC30
Analysis of VBS exploit CVE-2018-8174
CVE-2018-8174HIGHbajo ataqueransomware10 jul 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC5
XML external entity (XXE) vulnerability in /ssc/fm-ws/services in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (0day CVE-2018-12463)
CVE-2018-12463HIGH10 jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RIESGO
abrir
GitHub PoC1
lonehand/Oracle-WebLogic-CVE-2017-10271-master
CVE-2017-10271HIGHbajo ataqueransomware06 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC3
likekabin/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque02 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
anteriorpágina 440 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.