Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.610exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 may 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
CVE-2020-1938 exploit
CVE-2020-1938CRITICALbajo ataque12 may 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Dilan-Diaz/Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-
CVE-2020-8597CRITICAL12 may 2020
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
53RIESGO
abrir
GitHub PoC
janod313/-CVE-2019-14287-SUDO-bypass-vulnerability
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
DewmiApsara/CVE-2019-14287
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
SNP Assignment 1 Report - Linux box exploitation ( Vulnerability CVE-2014-0038)
CVE-2014-003812 may 2020
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
GitHub PoC
Glibc-Vulnerability-Exploit-CVE-2015-7547
CVE-2015-754712 may 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC
SachinThanushka/CVE-2018-1160
CVE-2018-1160CRITICAL12 may 2020
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALbajo ataque12 may 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
This is about CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque12 may 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
ShianTrish/sudo-Security-Bypass-vulnerability-CVE-2019-14287
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
This is a brief exploitation of CVE-2019-14287 Sudo Security Bypass Vulnerability.
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 may 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir
GitHub PoC
This is the exploitation of sudo security bypass vulnerability
CVE-2019-1428712 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
CVE-2019-5736
CVE-2019-573612 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
Sudo Security Policy bypass Vulnerability
CVE-2019-1428711 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287
CVE-2019-13272HIGHbajo ataque11 may 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC
Documentation for Sudo Security Bypass - CVE 2019-14287
CVE-2019-1428711 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
Exploit code for CVE-2015-5477 POC
CVE-2015-547711 may 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC1
Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153811 may 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC
shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-
CVE-2016-5195HIGHbajo ataque11 may 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC176
Weblogic coherence.jar RCE
CVE-2020-2883CRITICALbajo ataque10 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC
A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2020
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC10
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
CVE-2020-8816CRITICALbajo ataque10 may 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC
BBRathnayaka/POC-CVE-2019-5736
CVE-2019-573610 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
PoC for CVE-2020-11651
CVE-2020-11651CRITICALbajo ataque09 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC
Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.
CVE-2018-15473MEDIUM08 may 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC33
PoC CVE-2017-5123 - LPE - Bypassing SMEP/SMAP. No KASLR
CVE-2017-512308 may 2020
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC24
CVE-2020-11651&&CVE-2020-11652 EXP
CVE-2020-11651CRITICALbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC5
lovelyjuice/cve-2020-11651-exp-plus
CVE-2020-11651CRITICALbajo ataque07 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
anteriorpágina 399 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.