Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir
GitHub PoC1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
CVE-2020-8816CRITICALbajo ataque15 jun 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC
sionnx/cve-2003-0282
CVE-2003-028214 jun 2020
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RIESGO
abrir
GitHub PoC3
for 供養
CVE-2020-6418HIGHbajo ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
CVE-2020-0688HIGHbajo ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
CVE-2018-11776HIGHbajo ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
CVE-2017-9805HIGHbajo ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
批量测试CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALbajo ataqueransomware11 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
Norton Core Secure WiFi PoC (CVE-2018-5234) on Rust.
CVE-2018-523410 jun 2020
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir
GitHub PoC354
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
CVE-2020-0796CRITICALbajo ataqueransomware10 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC3
SMBv3 Ghost (CVE-2020-0796) Vulnerability
CVE-2020-0796CRITICALbajo ataqueransomware09 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
ratiros01/CVE-2004-1561
CVE-2004-156109 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC5
Bludit >= 3.9.2 - Authenticated RCE (CVE-2019-16113)
CVE-2019-1611309 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC
适配12.2.1.3和12.2.1.4版本
CVE-2020-2883CRITICALbajo ataque09 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC3
This is the exploit of CVE-2019-17240.
CVE-2019-17240LOW08 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC72
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
CVE-2019-2215HIGHbajo ataque07 jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC13
CVE-2019-16113 - bludit >= 3.9.2 RCE authenticate
CVE-2019-1611304 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC5
ynots0ups/CVE-2019-16113
CVE-2019-1611303 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC3
Data Collection Related to Exim CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque03 jun 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
CVE-2020-5410
CVE-2020-5410HIGHbajo ataque03 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC5
Exploit for CVE-2020-9283 based on Go
CVE-2020-928302 jun 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RIESGO
abrir
GitHub PoC
CVE-2020-0796-exp
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC89
PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)
CVE-2020-395601 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
GitHub PoC3
nmurilo/CVE-2008-4687-exploit
CVE-2008-468730 may 2020
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
GitHub PoC5
The reproduction code for CVE-2019-8641.
CVE-2019-864129 may 2020
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
GitHub PoC2
This project for CVE-2019-18935
CVE-2019-18935CRITICALbajo ataqueransomware29 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque29 may 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC
halsten/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware28 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC55
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437CRITICALbajo ataque27 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
anteriorpágina 396 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.