Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.974 exploits
GitHub PoC8
PoC for CVE-2019-19844 ( https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ )
CVE-2019-1984425 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
GitHub PoC78
Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
CVE-2019-17571CRITICAL25 dic 2019
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RIESGO
abrir
GitHub PoC8
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
CVE-2019-15107CRITICALbajo ataqueransomware25 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC3
CVE-2018-6389: WordPress <= 4.9.x 拒绝服务(DOS)漏洞
CVE-2018-638922 dic 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC1
my extended take on Mark Brand's CVE 2016-3861 libutils bug
CVE-2016-386121 dic 2019
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RIESGO
abrir
GitHub PoC645
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
CVE-2018-595521 dic 2019
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
GitHub PoC100
PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)
CVE-2019-1984421 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
GitHub PoC
Mass exploit for CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware20 dic 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC5
CVE-2019-10092 Docker - Apache HTTP Server
CVE-2019-1009218 dic 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RIESGO
abrir
GitHub PoC1
CVE-2018-9995 POC
CVE-2018-999516 dic 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC6
SmoZy92/CVE-2019-11932
CVE-2019-1193215 dic 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware15 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC3
Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.
CVE-2019-573612 dic 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
For test
CVE-2019-3396CRITICALbajo ataqueransomware12 dic 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
CVE-2019-2725-POC
CVE-2019-2725HIGHbajo ataqueransomware12 dic 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC5
Netis router RCE exploit ( CVE-2019-19356)
CVE-2019-19356HIGHbajo ataque12 dic 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RIESGO
abrir
GitHub PoC373
RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.
CVE-2019-18935CRITICALbajo ataqueransomware12 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC30
详解 k8gege的SharePoint RCE exploit cve-2019-0604-exp.py的代码,动手制作自己的payload
CVE-2019-0604CRITICALbajo ataqueransomware10 dic 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC
CVE-2014-1322 - IPC Local Security Bypass | Mac OSX (Affected. >= 10.9.2)
CVE-2014-132210 dic 2019
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RIESGO
abrir
GitHub PoC1
FreePBX exploit <= 2.8.0
CVE-2010-349009 dic 2019
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RIESGO
abrir
GitHub PoC1
CVE-2008-1611 TFTP 1.41 buffer overflow exploit in the filepath
CVE-2008-161108 dic 2019
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir
GitHub PoC109
CVE-2019-0708 (BlueKeep)
CVE-2019-0708CRITICALbajo ataqueransomware07 dic 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
CVE-2019-11510CRITICALbajo ataqueransomware07 dic 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC3
AppXSvc Arbitrary File Overwrite DoS
CVE-2019-147605 dic 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RIESGO
abrir
GitHub PoC12
This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3
CVE-2019-1957604 dic 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RIESGO
abrir
GitHub PoC21
hekadan/CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque01 dic 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC1
IE7 buffer overflow through an ANI file
CVE-2007-003829 nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
GitHub PoC72
guest→system(UAC手动提权)
CVE-2019-1388HIGHbajo ataqueransomware27 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC4
Exploit for CVE-2017-12945.
CVE-2017-1294527 nov 2019
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RIESGO
abrir
GitHub PoC6
Python script to exploit RCE in Nostromo nhttpd <= 1.9.6.
CVE-2019-16278CRITICALbajo ataque26 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
anteriorpágina 411 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.