Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.894exploits catalogados
35.202CVEs con explotación pública
24.695probados en laboratorio
13.976 exploits
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHbajo ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC14
CVE-2019-11043 PHP7.x RCE
CVE-2019-11043HIGHbajo ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC13
vesche/CVE-2019-10475
CVE-2019-1047506 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RIESGO
abrir
GitHub PoC3
CVE-2019-11043 && PHP7.x && RCE EXP
CVE-2019-11043HIGHbajo ataqueransomware06 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC3
CVE-2017-3506
CVE-2017-3506HIGHbajo ataque05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC2
(CVE-2017-10271)Java反序列化漏洞
CVE-2017-10271HIGHbajo ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC4
PoC for Webmin Package Update Authenticated Remote Command Execution
CVE-2019-1284005 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC
Optional Mitigation Steps
CVE-2019-1231405 nov 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RIESGO
abrir
GitHub PoC3
CVE-2019-2725
CVE-2019-2725HIGHbajo ataqueransomware05 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC2
CVE-2018-3245
CVE-2018-324505 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
45RIESGO
abrir
GitHub PoC
CVE-2017-3248
CVE-2017-324805 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
GitHub PoC1
CVE-2017-0005 POC
CVE-2017-0005HIGHbajo ataque05 nov 2019
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
76RIESGO
abrir
GitHub PoC3
POC for CVE-2019-13720
CVE-2019-13720HIGHbajo ataque04 nov 2019
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RIESGO
abrir
GitHub PoC
Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2
CVE-2017-1161002 nov 2019
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
GitHub PoC
CVE-2018-15473-Exploit
CVE-2018-15473MEDIUM01 nov 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
3rg1s/CVE-2016-2098
CVE-2016-209830 oct 2019
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC8
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
CVE-2019-11043HIGHbajo ataqueransomware30 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC10
Mayter/CVE-2019-1315
CVE-2019-1315HIGHbajo ataqueransomware29 oct 2019
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
71RIESGO
abrir
GitHub PoC5
Python exp for CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware29 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC1
CVE-2019-11043 PHP远程代码执行
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC146
(PoC) Python version of CVE-2019-11043 exploit by neex
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
TEST
CVE-2019-3396CRITICALbajo ataqueransomware28 oct 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
huang919/cve-2019-14287-PPT
CVE-2019-1428728 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC19
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10149CRITICALbajo ataque27 oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC7
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
CVE-2019-1887327 oct 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RIESGO
abrir
GitHub PoC4
apache axis1.4远程代码执行漏洞
CVE-2019-022727 oct 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RIESGO
abrir
GitHub PoC2
CVE-2000-0979
CVE-2000-097926 oct 2019
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RIESGO
abrir
GitHub PoC3
Remote Code Execution Vulnerability in Webmin
CVE-2019-15107CRITICALbajo ataqueransomware24 oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC1
fairyming/CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
anteriorpágina 413 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.