Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC289
Exploit for CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware13 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
Starry-lord/CVE-2018-0114
CVE-2018-011413 ene 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC1
CVE-2017-12615 任意文件写入exp,写入webshell
CVE-2017-12615HIGHbajo ataqueransomware12 ene 2021
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC
AnasTaoutaou/CVE-2019-5420
CVE-2019-542011 ene 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC8
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
CVE-2020-17519CRITICALbajo ataque10 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC5
ElmouradiAmine/CVE-2020-7048
CVE-2020-7048CRITICAL09 ene 2021
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any
53RIESGO
abrir
GitHub PoC
CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque08 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC5
uzzzval/CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque07 ene 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC7
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs
CVE-2020-1472MEDIUMbajo ataqueransomware07 ene 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC3
Python implementation of Roundcube LFI (CVE-2017-16651)
CVE-2017-16651HIGHbajo ataque06 ene 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir
GitHub PoC3
Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC48
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC1
QmF0c3UK/CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC10
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
CVE-2020-10148CRITICALbajo ataque05 ene 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
GitHub PoC1
andyfeili/CVE-2014-4688
CVE-2014-468805 ene 2021
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir
GitHub PoC99
CISCO CVE-2020-3452 Scanner & Exploiter
CVE-2020-3452HIGHbajo ataque05 ene 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC16
Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)
CVE-2020-29583CRITICALbajo ataque04 ene 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RIESGO
abrir
GitHub PoC21
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
CVE-2020-0688HIGHbajo ataqueransomware04 ene 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC2
python2.7 script for JWT generation
CVE-2018-011403 ene 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC3
AzhariKun/CVE-2018-15133
CVE-2018-15133HIGHbajo ataque03 ene 2021
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
andyfeili/CVE-2018-9276
CVE-2018-9276HIGHbajo ataque02 ene 2021
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
GitHub PoC5
A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous Cipher [CVE-2012-4929] CRIME(SPDY) [CVE-2014-0160] CCS Injection [CVE-2014-0224] HeartBleed [CVE-2014-3566] SSLv3 POODLE [CVE-2015-0204] FREAK Attack [CVE-2015-4000] LOGJAM Attack [CVE-2016-0800] SSLv2 DROWN Installation : $ apt update && apt upgrade $ apt install git $ apt install python2 $ apt install python $ git clone https://github.com/hahwul/ a2sv $ cd a2sv $ chmod +x * $ pip2 install -r requirements.txt usage : $ python2 a2sv.py -h It shows all commands how we can use this tool $ python a2sv.py -t 127.0.0.1 127.0.0.1 = target means here own device
CVE-2014-0160HIGHbajo ataque01 ene 2021
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
zerologon script to exploit CVE-2020-1472 CVSS 10/10
CVE-2020-1472MEDIUMbajo ataqueransomware01 ene 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Cisco IP Phone 11.7 - Denial of Service (PoC)
CVE-2020-3161CRITICALbajo ataque31 dic 2020
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RIESGO
abrir
GitHub PoC2
Todos los materiales necesarios para la PoC en Chrome y ftview
CVE-2020-15999CRITICALbajo ataque30 dic 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC4
CyborgSecurity/CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque30 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC1
Repositorio con un script encargado de explotar la vulnerabilidad CVE-2020-15999
CVE-2020-15999CRITICALbajo ataque30 dic 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC13
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。
CVE-2020-14882CRITICALbajo ataque30 dic 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC5
rdoix/CVE-2020-10148-Solarwinds-Orion
CVE-2020-10148CRITICALbajo ataque29 dic 2020
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
GitHub PoC
cve-2018-1133 moodle athenticated as teacher remote code execution.
CVE-2018-113326 dic 2020
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RIESGO
abrir
anteriorpágina 382 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.