Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8607Nuclei 4255Metasploit 3474✓ solo verificadosrecientespopularesriesgo
14.080 exploits
GitHub PoC★ 4
Source code and configuration files related to our article in MISC96
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir ↗GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RIESGO
abrir ↗GitHub PoC★ 2
CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 1
cve-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC
alessiogilardi/PoC---CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 82
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir ↗GitHub PoC★ 1
This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC
MaxSecurity/Office-CVE-2017-8570
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗GitHub PoC
BlackRouter/cve-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
Proof of Concept of vunerability CVE-2018-6389 on Wordpress 4.9.2
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
CVE-2018-4878 样本
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC★ 59
CVE-2018-4087 PoC
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir ↗GitHub PoC★ 1
RavSS/Bluetooth-Crash-CVE-2017-0785
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗GitHub PoC★ 3
HanseSecure/CVE-2009-1437
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir ↗GitHub PoC★ 1
Containerized exploitable PhpCollab
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir ↗GitHub PoC★ 1
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir ↗GitHub PoC★ 29
CVE-2009-2698 compiled for CentOS 4.8
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo
23RIESGO
abrir ↗GitHub PoC★ 6
Struts02 s2-045 exploit program
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC
Global Fix for Wordpress CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 3
CVE-2015-5374 Denial of Service PoC
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RIESGO
abrir ↗GitHub PoC★ 9
ChakraCore exploitation techniques
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir ↗GitHub PoC★ 86
Aggressor Script to launch IE driveby for CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC★ 6
PHPMailer < 5.2.18 Remote Code Execution Exploit
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC★ 2
Metasploit module for WordPress DOS load-scripts.php CVE-2018-638
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 23
mdsecactivebreach/CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC
Aggressor Script to just launch IE driveby for CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC
Code put together from a few peoples ideas credit given don't use maliciously please
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir ↗GitHub PoC★ 8
Exploit for CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RIESGO
abrir ↗GitHub PoC★ 16
Ruby On Rails unrestricted render() exploit
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗GitHub PoC★ 2
Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.