Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.060exploits catalogados
35.302CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC3
Proof of concept showing how CVE-2016-2098 leads to remote code execution
CVE-2016-209801 mar 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC45
Exploiting CVE-2016-0040 uninitialized pointer
CVE-2016-0040HIGHbajo ataque26 feb 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
GitHub PoC
CVE-2015-0235
CVE-2015-023525 feb 2016
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC1
Elm0D/CVE-2017-8464
CVE-2017-8464HIGHbajo ataque24 feb 2016
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC
glibc getaddrinfo stack-based buffer overflow
CVE-2015-754721 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC51
Automated Exploit Toolkit for CVE-2015-6095 and CVE-2016-0049
CVE-2016-004918 feb 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
GitHub PoC
glibc check and update in light of CVE-2015-7547
CVE-2015-754718 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC1
t0r0t0r0/CVE-2015-7547
CVE-2015-754717 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC5
test script for CVE-2015-7547
CVE-2015-754717 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC1
Heartbleed
CVE-2014-0160HIGHbajo ataque16 feb 2016
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC16
CVE-2016-1287 vulnerability test
CVE-2016-128715 feb 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir
GitHub PoC
Gitlabpro/The-analysis-of-the-cve-2015-8651
CVE-2015-8651HIGHbajo ataque12 feb 2016
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef
83RIESGO
abrir
GitHub PoC543
Proof of concept for CVE-2015-7547
CVE-2015-754710 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC323
EoP (Win7) & BSoD (Win10) PoC for CVE-2016-0051 (MS-016)
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
GitHub PoC
CVE-2015-8562 Exploit in bash
CVE-2015-856208 feb 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC41
Trigger and exploit code for CVE-2014-4113
CVE-2014-4113HIGHbajo ataque07 feb 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
GitHub PoC30
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
GitHub PoC5
A testbed for CVE-2016-0728, a refcount leak/overflow bug in Linux
CVE-2016-072828 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC10
forced-request/rails-rce-cve-2016-0752
CVE-2016-0752HIGHbajo ataque26 ene 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
GitHub PoC
googleweb/CVE-2016-0728
CVE-2016-072823 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC22
nardholio/cve-2016-0728
CVE-2016-072822 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC5
Exploit CVE-2014-4113
CVE-2014-4113HIGHbajo ataque22 ene 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
GitHub PoC3
CVE-2016-0728 Linux Kernel Vulnerability
CVE-2016-072820 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC1
idl3r/cve-2016-0728
CVE-2016-072819 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC67
PoC for CVE-2015-6086
CVE-2015-608618 ene 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RIESGO
abrir
GitHub PoC2
cinno/CVE-2015-7755-POC
CVE-2015-7755CRITICALbajo ataque09 ene 2016
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir
GitHub PoC2
A proof of concept for Joomla's CVE-2015-8562 vulnerability
CVE-2015-856204 ene 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC8
All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.
CVE-2015-856204 ene 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC3
ockeghem/CVE-2015-6835-checker
CVE-2015-683519 dic 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir
GitHub PoC105
Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS
CVE-2015-7755CRITICALbajo ataque18 dic 2015
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir
anteriorpágina 463 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.