Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.937VulnCheck XDB 8510Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
13.937 exploits
GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC★ 1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC
POC-CVE-2020-7961-Token-iterate
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗GitHub PoC
DarkFlameMaster-bit/CVE-2018-8174_EXP
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗GitHub PoC
qianniaoge/CVE-2020-14882_Exploit_Gui
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗GitHub PoC
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir ↗GitHub PoC
Qualcomm GPU / ARM Mali GPU
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
71RIESGO
abrir ↗GitHub PoC★ 4
WordPress XXE vulnerability
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC
bgsilvait/WIn-CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗GitHub PoC★ 8
PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RIESGO
abrir ↗GitHub PoC
tuo4n8/CVE-2020-2950
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana
70RIESGO
abrir ↗GitHub PoC★ 8
POC for exiftool vuln (CVE-2021-22204).
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir ↗GitHub PoC★ 24
ch3rn0byl/CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir ↗GitHub PoC★ 1
RCE
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir ↗GitHub PoC
Local Privilege Escalation is a way to take advantage of flaws in code or service administration that can manage regular or guest users for particular device activities or transfer root user privileges to master or client. User rights admin. The licenses or privileges may be violated by such undesired amendments, as the system may be disrupted by frequent users unless they have shell or root authorization. So, someone, someone, it may become dangerous and be used to obtain access to a higher level.
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗GitHub PoC
CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 1
Docker image that lets me study the exploitation of the VIM exploit
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir ↗GitHub PoC★ 5
simple bash script for exploit CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 12
HTTP Protocol Stack CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 53
PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir ↗GitHub PoC★ 1
Nmap NSE script to detect CVE-2019-14322 of Pallets Werkzeug path traversal via SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir ↗GitHub PoC★ 8
PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 3
Different rules to detect if CVE-2021-31166 is being exploited
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 827
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir ↗GitHub PoC★ 60
RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir ↗GitHub PoC★ 2
Pega Infinity Password Reset
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir ↗GitHub PoC★ 1
0xm4ud/ProFTPD_CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗GitHub PoC★ 4
Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.