Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC
Wh1t3Fox/cve-2018-15473
CVE-2018-15473MEDIUM02 sep 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciript
CVE-2019-2725HIGHbajo ataqueransomware31 ago 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC1
(CVE-2020-3452) Cisco Adaptive Security Appliance Software - Local File Inclusion Vuln Test sciript
CVE-2020-3452HIGHbajo ataque31 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2018-7600CRITICALbajo ataqueransomware31 ago 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC3
PoC of Full Account Takeover on RAD SecFlow-1v
CVE-2020-1325931 ago 2020
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauth
23RIESGO
abrir
GitHub PoC1
(CVE-2017-5638) XworkStruts RCE Vuln test script
CVE-2017-5638CRITICALbajo ataqueransomware31 ago 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC4
(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE
CVE-2019-6340HIGHbajo ataque31 ago 2020
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC1
(CVE-2019-16759) vBulletin_Routestring-RCE
CVE-2019-16759CRITICALbajo ataque31 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC22
Tool to test for existence of CVE-2020-8218
CVE-2020-8218HIGHbajo ataque29 ago 2020
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform
83RIESGO
abrir
GitHub PoC22
[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)
CVE-2017-9822HIGHbajo ataqueransomware28 ago 2020
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
GitHub PoC47
An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).
CVE-2019-17026HIGHbajo ataque27 ago 2020
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RIESGO
abrir
GitHub PoC
This CVE-2018-8120 File
CVE-2018-8120HIGHbajo ataqueransomware27 ago 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware26 ago 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC2
Exploit for CVE-2019-16724
CVE-2019-1672425 ago 2020
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
GitHub PoC1
sunian19/CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque24 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC
CVE-2017-8570 Exp及利用样本分析
CVE-2017-0261HIGHbajo ataque22 ago 2020
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar
93RIESGO
abrir
GitHub PoC
starling021/CVE-2019-11932-SupportApp
CVE-2019-1193220 ago 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC1
ctlyz123/CVE-2020-17496
CVE-2020-17496CRITICALbajo ataque20 ago 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RIESGO
abrir
GitHub PoC35
CVE-2019-0230 & s2-059 poc.
CVE-2019-023020 ago 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
GitHub PoC16
[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization
CVE-2019-18935CRITICALbajo ataqueransomware19 ago 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC532
WebLogic利用CVE-2020-2883打Shiro rememberMe反序列化漏洞,一键注册蚁剑filter内存shell
CVE-2020-2883CRITICALbajo ataque19 ago 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC
Logeirs/CVE-2018-0114
CVE-2018-011418 ago 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
superzerosec/cve-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware18 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC4
[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)
CVE-2020-0688HIGHbajo ataqueransomware17 ago 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC1
cyberharsh/PHP_CVE-2012-1823
CVE-2012-1823CRITICALbajo ataque17 ago 2020
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC6
This tools will extracts and dumps Email + SMTP from vBulletin database server
CVE-2019-16759CRITICALbajo ataque16 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC3
dwisiswant0/CVE-2020-9496
CVE-2020-949615 ago 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC2
[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)
CVE-2020-5902CRITICALbajo ataqueransomware13 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC2
[CVE-2016-2386] SAP NetWeaver AS JAVA UDDI Component SQL Injection
CVE-2016-2386CRITICALbajo ataque13 ago 2020
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC7
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
CVE-2020-3452HIGHbajo ataque13 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
anteriorpágina 390 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.