Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC
homjxi0e/CVE-2017-9430
CVE-2017-943008 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-7472
CVE-2017-747208 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RIESGO
abrir
GitHub PoC
smancke/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware07 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC84
Motorola Untethered Jailbreak: Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027706 jun 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
GitHub PoC259
Remote root exploit for the SAMBA CVE-2017-7494 vulnerability
CVE-2017-7494CRITICALbajo ataqueransomware05 jun 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC1
homjxi0e/CVE-2017-1000367
CVE-2017-100036704 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
GitHub PoC56
Exploiting CVE-2016-4657 to JailBreak the Nintendo Switch
CVE-2016-4657HIGHbajo ataque02 jun 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
GitHub PoC114
c0d3z3r0/sudo-CVE-2017-1000367
CVE-2017-100036730 may 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
GitHub PoC119
Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.
CVE-2017-600830 may 2017
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RIESGO
abrir
GitHub PoC57
It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).
CVE-2017-7494CRITICALbajo ataqueransomware30 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC1
An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware27 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC63
CVE-2017-7494 - Detection Scripts
CVE-2017-7494CRITICALbajo ataqueransomware26 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC381
SambaCry exploit and vulnerable container (CVE-2017-7494)
CVE-2017-7494CRITICALbajo ataqueransomware26 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-7494
CVE-2017-7494CRITICALbajo ataqueransomware25 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC181
Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)
CVE-2017-7494CRITICALbajo ataqueransomware25 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC21
k0keoyo/CVE-2015-2546-Exploit
CVE-2015-2546HIGHbajo ataqueransomware25 may 2017
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RIESGO
abrir
GitHub PoC3
Admidio 3.2.8 Cross-Site Request Forgery Assigned CVE Number: CVE-2017-8382
CVE-2017-838221 may 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir
GitHub PoC
WordPress 4.6 - Remote Code Execution (RCE) PoC Exploit
CVE-2016-10033CRITICALbajo ataque19 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC7
Joomla 3.7 SQL injection (CVE-2017-8917)
CVE-2017-891719 may 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC
Install patch for CVE-2017-0145 AKA WannaCry.
CVE-2017-0145HIGHbajo ataqueransomware19 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC3
Simple script using nmap to detect CVE-2017-0143 MS17-010 in your network
CVE-2017-0143HIGHbajo ataqueransomware16 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
cve-2016-0728 exploit and summary
CVE-2016-072816 may 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC88
CVE-2017-7269 to webshell or shellcode loader
CVE-2017-7269CRITICALbajo ataque16 may 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC1
Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689
CVE-2017-5689CRITICALbajo ataque12 may 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
GitHub PoC1
Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALbajo ataque11 may 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-0290-
CVE-2017-029011 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RIESGO
abrir
GitHub PoC1
Code and vulnerable WordPress container for exploiting CVE-2016-10033
CVE-2016-10033CRITICALbajo ataque10 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC9
RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html
CVE-2016-10033CRITICALbajo ataque10 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
anteriorpágina 455 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.