Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
14.080 exploits
GitHub PoC
CVE-2017-7494 C poc
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC★ 2
DVR系列摄像头批量检测
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC
CVE-2017-0411 PoC refered p0
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir ↗GitHub PoC★ 4
CVE-2018-9995_Batch_scanning_exp
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC
Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗GitHub PoC
CS4238 Computer Security Practices
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 1
WP-DOS-Exploit-CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 2
Empire Port of CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 114
Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 6
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir ↗GitHub PoC★ 9
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by "xlink:href=file://192.168.0.2/test.jpg" within an "office:document-content" element in a ".odt XML document".
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir ↗GitHub PoC★ 1
Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 31
PoC exploit for CVE-2018-5234
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir ↗GitHub PoC★ 557
(CVE-2018-9995) Get DVR Credentials
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC★ 11
Al1ex/CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗GitHub PoC★ 6
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗GitHub PoC★ 13
CVE-2017-16995(Ubuntu本地提权漏洞)
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗GitHub PoC
CVE-2018-9160
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗GitHub PoC★ 2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC
herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 2
Shadowshusky/CVE-2018-2628all
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC
shaoshore/CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC
mudhappy/Wordpress-Hack-CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 1
xssfile/CVE-2017-8464-EXP
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗GitHub PoC
CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RIESGO
abrir ↗GitHub PoC★ 119
macOS 10.13.3 (17D47) Safari Wasm Exploit
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir ↗GitHub PoC★ 1
9uest/CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 11
Exploit for CVE-2018-7600.. called drupalgeddon2,
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 78
CVE-2018-2628 & CVE-2018-2893
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.