Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
14.014 exploits
GitHub PoC★ 3
CVE 2019-2215 Android Binder Use After Free
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC★ 38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 17
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC
gurneesh/CVE-2019-14287-write-up
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 1
Exploit and Mass Pwn3r for CVE-2019-16920
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RIESGO
abrir ↗GitHub PoC★ 10
Standalone Python 3 exploit for CVE-2017-17562
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir ↗GitHub PoC★ 70
Directory transversal to remote code execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗GitHub PoC★ 9
CVE-2019-16728 Proof of Concept
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2019-16278Nostromo httpd命令执行
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗GitHub PoC★ 1
This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 13
Sudo exploit
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 1
FauxFaux/sudo-cve-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 12
CVE-2018-13379 Script for Nmap NSE.
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir ↗GitHub PoC★ 134
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC
Spring Security OAuth 2.3 Open Redirection 分析复现篇
Open Redirect in spring-security-oauth2
28RIESGO
abrir ↗GitHub PoC★ 4
Interactive-Like Command-Line Console for CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗GitHub PoC
h-wookie/cve-2019-5736-poc
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir ↗GitHub PoC★ 1
CVE-2018-7600 and CVE-2018-7602 Mass Exploiter
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 10
PoC materials to exploit CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir ↗GitHub PoC★ 16
Critical Remote Code Execution Vulnerability (CVE-2018-11776) Found in Apache Struts.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 2
The study of vulnerability CVE-2017-3066. Java deserialization
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir ↗GitHub PoC★ 2
KRAMER VIAware 2.5.0719.1034 - Remote Code Execution
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RIESGO
abrir ↗GitHub PoC
Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 4
infiniteLoopers/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 4
Double-Free BUG in WhatsApp exploit poc.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 208
Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 4
This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 77
timwr/CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir ↗GitHub PoC
Rails 3 PoC of CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir ↗GitHub PoC★ 8
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 | XSS to RCE
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.