Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.974 exploits
GitHub PoC
Exploit the dirtycow vulnerability to login as root
CVE-2016-5195HIGHbajo ataque26 nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC7
timwr/CVE-2019-5825
CVE-2019-5825MEDIUMbajo ataque23 nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC
crispy-peppers/Goahead-CVE-2017-17562
CVE-2017-17562HIGHbajo ataque23 nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
crispy-peppers/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL23 nov 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC8
A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.
CVE-2019-16278CRITICALbajo ataque22 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC1
ulisesrc/-2-CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware22 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC20
CVE-2019-0232-Remote Code Execution on Apache Tomcat 7.0.42
CVE-2019-023221 nov 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC193
CVE-2019-1388 UAC提权 (nt authority\system)
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
jaychouzzk/CVE-2019-1388
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
am6539/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC1
l-iberty/cve-2012-1889
CVE-2012-1889HIGHbajo ataque20 nov 2019
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir
GitHub PoC5
random-robbie/CVE-2019-5418
CVE-2019-5418HIGHbajo ataque19 nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC51
Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894
CVE-2020-0796CRITICALbajo ataqueransomware19 nov 2019
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
remote debug environment for CLion
CVE-2019-11043HIGHbajo ataqueransomware17 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2019-1428713 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC348
Privilege Escalation: Weaponizing CVE-2019-1405 and CVE-2019-1322
CVE-2019-1405HIGHbajo ataqueransomware13 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALbajo ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Sindayifu/CVE-2019-14287-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque13 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RIESGO
abrir
GitHub PoC
Sindadziy/cve-2014-6271
CVE-2014-6271CRITICALbajo ataque12 nov 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Sindadziy/cve-2019-14287
CVE-2019-1428712 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
cve-2019-14287
CVE-2019-1428711 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHbajo ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC13
The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
GitHub PoC8
A standalone POC for CVE-2019-12840
CVE-2019-1284009 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC1
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
CVE-2019-1302408 nov 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RIESGO
abrir
GitHub PoC1
phongld97/detect-cve-2018-16858
CVE-2018-16858HIGH07 nov 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
GitHub PoC10
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263507 nov 2019
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHbajo ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
anteriorpágina 412 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.