Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC3
CVE-2017-12615 Tomcat RCE (TESTED)
CVE-2017-12615HIGHbajo ataqueransomware26 dic 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC3
Simplified PoC for Weblogic-CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware25 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC22
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
CVE-2017-10271HIGHbajo ataqueransomware25 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC26
CVE-2017-17215 HuaWei Router RCE (NOT TESTED)
CVE-2017-1721525 dic 2017
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
GitHub PoC39
CVE-2017-10271 WEBLOGIC RCE (TESTED)
CVE-2017-10271HIGHbajo ataqueransomware23 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC15
CVE-2017-12149 JBOSS RCE (TESTED)
CVE-2017-12149CRITICALbajo ataqueransomware22 dic 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC2
CVE-2017-15944 Palo Alto Networks firewalls remote root code execution POC
CVE-2017-15944CRITICALbajo ataque19 dic 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC15
Sudo <= 1.8.14 Local Privilege Escalation and vulnerable container
CVE-2015-560216 dic 2017
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
GitHub PoC3
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
CVE-2017-0199HIGHbajo ataqueransomware08 dic 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC
acidburnmi/CVE-2016-5195-master
CVE-2016-5195HIGHbajo ataque06 dic 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC21
Better Exploit Code For CVE 2017 9805 apache struts
CVE-2017-9805HIGHbajo ataque04 dic 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
chu1337/CVE-2017-1000117
CVE-2017-100011703 dic 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
giovannidispoto/CVE-2017-13872-Patch
CVE-2017-1387230 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
GitHub PoC200
A POC for the Huge Dirty Cow vulnerability (CVE-2017-1000405)
CVE-2017-100040529 nov 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
GitHub PoC210
CVE-2017-12149 jboss反序列化 可回显
CVE-2017-12149CRITICALbajo ataqueransomware28 nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC1
Tomcat 远程代码执行漏洞 Exploit
CVE-2017-12615HIGHbajo ataqueransomware28 nov 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
CVE-2017-9805 - Exploit
CVE-2017-9805HIGHbajo ataque28 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC2
Shadowshusky/CVE-2017-11882-
CVE-2017-11882HIGHbajo ataqueransomware27 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC2
CVE-2015-4852 Oracle WebLogic Scanner
CVE-2015-4852CRITICALbajo ataque25 nov 2017
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
GitHub PoC15
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHbajo ataque24 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
CSC-pentest/cve-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware24 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
# CVE-2017-11882-metasploit This is a Metasploit module which exploits CVE-2017-11882 using the POC below: https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about. ## Installation 1) Copy the cve_2017_11882.rb to /usr/share/metasploit-framework/modules/exploits/windows/local/ 2) Copy the cve-2017-11882.rtf to /usr/share/metasploit-framework/data/exploits/ This module is a quick port to Metasploit and uses mshta.exe to execute the payload. There are better ways to implement this module and exploit but will update it as soon as I have the time.
CVE-2017-11882HIGHbajo ataqueransomware24 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC3
Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.
CVE-2014-6271CRITICALbajo ataque23 nov 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
CVE-2017-9430 Fix
CVE-2017-943022 nov 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
GitHub PoC44
CVE-2017-11882 exploitation
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
Grey-Li/CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC34
CVE-2017-11882 File Generator PoC
CVE-2017-11882HIGHbajo ataqueransomware21 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC22
CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)
CVE-2017-12149CRITICALbajo ataqueransomware21 nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC
CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware21 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC98
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
CVE-2017-11882HIGHbajo ataqueransomware21 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
anteriorpágina 449 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.