Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC
Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM15 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
GitHub PoC17
a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM14 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware12 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2018-0802HIGHbajo ataque12 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2018-0802HIGHbajo ataque11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2017-11882HIGHbajo ataqueransomware11 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC68
Exploit the vulnerability to execute the calculator
CVE-2018-0802HIGHbajo ataque11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC9
8.4.1 Jailbreak using CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMbajo ataque09 ene 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2017-11317CRITICALbajo ataque09 ene 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
GitHub PoC54
Spectre exploit
CVE-2017-5715MEDIUM09 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware09 ene 2018
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC185
Proof of Concept exploit for CVE-2017-8570
CVE-2017-8570HIGHbajo ataque09 ene 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
GitHub PoC11
TwonkyMedia Server 7.0.11-8.5 Directory Traversal CVE-2018-7171
CVE-2018-717109 ene 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RIESGO
abrir
GitHub PoC1
OSX 10.13.2, CVE-2017-5753, Spectre, PoC, C, ASM for OSX, MAC, Intel Arch, Proof of Concept, Hopper.App Output
CVE-2017-5753MEDIUM07 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
Simply diff for CVE-2017-0785
CVE-2017-078507 ene 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC7
The demo of the speculative execution attack Spectre (CVE-2017-5753, CVE-2017-5715).
CVE-2017-5753MEDIUM06 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC1
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM06 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC12
2018年1月2日 (CVE-2017-5753 和 CVE-2017-5715) "幽灵" Spectre 漏洞利用
CVE-2017-5753MEDIUM05 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC129
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
CVE-2017-10271HIGHbajo ataqueransomware05 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
A Simple PoC for CVE-2012-4681
CVE-2012-4681CRITICALbajo ataqueransomware05 ene 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir
GitHub PoC771
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC4
Spectre (CVE-2017-5753) (CVE-2017-5715). Not By Me. Collected from Book.
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
specloli/CVE-2017-17692
CVE-2017-1769204 ene 2018
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RIESGO
abrir
GitHub PoC3
forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.Modified by hanc00l
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC2
credit to artkond
CVE-2017-3881CRITICALbajo ataque02 ene 2018
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2003-0264 based on pwntools and metasploit's windows/reverse_tcp
CVE-2003-026401 ene 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
GitHub PoC15
xyzAsian/Janus-CVE-2017-13156
CVE-2017-1315629 dic 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC143
WebLogic Exploit
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC29
CVE-2017-10271 POC
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC1
CVE-2017-17562 GOAHEAD RCE (Author: Daniel Hodson)
CVE-2017-17562HIGHbajo ataque27 dic 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
anteriorpágina 448 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.