Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC
Aruthw/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque30 jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
qy1202/https-github.com-Ridter-CVE-2017-11882-
CVE-2017-11882HIGHbajo ataqueransomware28 jun 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page, which includes an exploit for CVE-2018-8174 and shellcode. This enables remote code execution of the shellcode obfuscated in the landing page. After successful exploitation, a second-stage downloader is retrieved, which appears to be a variant of SmokeLoader due to the URL. It would then download the final payload, a Monero miner.
CVE-2018-8174HIGHbajo ataqueransomware26 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
stevenlinfeng/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque26 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC11
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware26 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process.
CVE-2018-995825 jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
GitHub PoC
guwudoor/CVE-2018-8214
CVE-2018-821425 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
GitHub PoC520
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALbajo ataque24 jun 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC
leandrocamposcardoso/CVE-2017-5638-Mass-Exploit
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
Cisco ASA - CVE-2018-0296 | Exploit
CVE-2018-0296HIGHbajo ataque22 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC
Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)
CVE-2018-1259621 jun 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir
GitHub PoC205
Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC107
Test CVE-2018-0296 and extract usernames
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC1
CVE-2017-5792
CVE-2017-579220 jun 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RIESGO
abrir
GitHub PoC9
MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)
CVE-2015-1635CRITICALbajo ataque20 jun 2018
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate
CVE-2018-3639MEDIUM19 jun 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC1
CVE-2016-2098 simple POC written in bash
CVE-2016-209819 jun 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC
Just a couple exploits for CVE-2018-11510
CVE-2018-1151018 jun 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
GitHub PoC7
Demo-ing CVE-2017-1000253 in a container
CVE-2017-1000253HIGHbajo ataqueransomware18 jun 2018
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RIESGO
abrir
GitHub PoC
Shellshock vulnerability attacker
CVE-2014-6271CRITICALbajo ataque18 jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC87
POC for CVE-2018-0824
CVE-2018-0824HIGHbajo ataque15 jun 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir
GitHub PoC
MySQL 4.x/5.0 (Linux) - User-Defined Function (UDF) Dynamic Library (2) automation script.
CVE-2012-561314 jun 2018
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir
GitHub PoC18
empty_list - exploit for p0 issue 1564 (CVE-2018-4243) iOS 11.0 - 11.3.1 kernel r/w
CVE-2018-424313 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir
GitHub PoC
CVE-2018-4878 flash 0day
CVE-2018-4878HIGHbajo ataqueransomware12 jun 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC11
A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.
CVE-2016-7255HIGHbajo ataque09 jun 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
GitHub PoC
teawater/CVE-2017-5123
CVE-2017-512308 jun 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC292
CVE-2018-8120 Exploit for Win2003 Win2008 WinXP Win7
CVE-2018-8120HIGHbajo ataqueransomware07 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC4
CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer
CVE-2018-424106 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
GitHub PoC3
Exploit for CVE-2018-10562
CVE-2018-10562CRITICALbajo ataqueransomware06 jun 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC107
Weblogic 反序列化漏洞(CVE-2018-2628)
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
anteriorpágina 441 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.