Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC55
Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.
CVE-2020-5902CRITICALbajo ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC374
CVE-2020-5902 BIG-IP
CVE-2020-5902CRITICALbajo ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC12
POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!
CVE-2020-5902CRITICALbajo ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC71
Proof of concept for CVE-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC8
nsflabs/CVE-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC
Simple OpenSSL TLS Heartbeat (CVE-2014-0160) Scanner and Exploit (Multiple SSL/TLS versions)
CVE-2014-0160HIGHbajo ataque04 jul 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC9
CVE-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware04 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC
Kenun99/CVE-2019-16113-Dockerfile
CVE-2019-1611303 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC17
The official exploit for OCS Inventory NG v2.7 Remote Command Execution CVE-2020-14947
CVE-2020-1494702 jul 2020
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec
28RIESGO
abrir
GitHub PoC2
reversebrain/CVE-2019-18988
CVE-2019-18988HIGHbajo ataque01 jul 2020
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for dif
86RIESGO
abrir
GitHub PoC1
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure (Python3)
CVE-2006-339230 jun 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
GitHub PoC19
CVE-2013-2028 python exploit
CVE-2013-202827 jun 2020
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
GitHub PoC
cyberharsh/Shellbash-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque26 jun 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
cyberharsh/DrupalCVE-2018-7602
CVE-2018-7602CRITICALbajo ataqueransomware25 jun 2020
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
GitHub PoC1
cyberharsh/Oracle-mysql-CVE-2012-2122
CVE-2012-212224 jun 2020
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - bruteforce bypass - CVE-2019-17240
CVE-2019-17240LOW24 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC
cyberharsh/Php-unit-CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque24 jun 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
cyberharsh/Tomcat-CVE-2017-12615
CVE-2017-12615HIGHbajo ataqueransomware24 jun 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
Python version of Metasploit exploit for CVE-2004-1561
CVE-2004-156122 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC
cyberharsh/Groovy-scripting-engine-CVE-2015-1427
CVE-2015-1427CRITICALbajo ataque22 jun 2020
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC3
cyberharsh/Nginx-CVE-2013-4547
CVE-2013-454720 jun 2020
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware20 jun 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
cyberharsh/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL19 jun 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC20
This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework
CVE-2020-0796CRITICALbajo ataqueransomware19 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC60
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
CVE-2020-816319 jun 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
GitHub PoC1
cyberharsh/Apache-couchdb-CVE-2017-12635
CVE-2017-1263519 jun 2020
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
CVE-2018-7600 0-Day Exploit (cyber-warrior.org)
CVE-2018-7600CRITICALbajo ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC721
Support ALL Windows Version
CVE-2020-0787HIGHbajo ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
GitHub PoC30
CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
CVE-2020-5410HIGHbajo ataque16 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC86
LPE for CVE-2020-1054 targeting Windows 7 x64
CVE-2020-1054HIGHbajo ataque16 jun 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RIESGO
abrir
anteriorpágina 395 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.