Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALbajo ataqueransomware11 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC63
securifera/CVE-2019-1579
CVE-2019-1579HIGHbajo ataqueransomware10 sep 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RIESGO
abrir
GitHub PoC
0x6b7966/CVE-2018-1999002
CVE-2018-199900210 sep 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RIESGO
abrir
GitHub PoC133
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
CVE-2019-11510CRITICALbajo ataqueransomware09 sep 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC1
CVE-2019-0708 RCE远程代码执行getshell教程
CVE-2019-0708CRITICALbajo ataqueransomware07 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC4
CVE-2019-0708 With Metasploit-Framework Exploit
CVE-2019-0708CRITICALbajo ataqueransomware07 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC12
initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.
CVE-2019-0708CRITICALbajo ataqueransomware07 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC11
CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware07 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
CVE-2019-0708RDP MSF
CVE-2019-0708CRITICALbajo ataqueransomware07 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC13
Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp
CVE-2019-0708CRITICALbajo ataqueransomware06 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC187
Root your MediaTek device with CVE-2020-0069
CVE-2020-0069HIGHbajo ataque06 sep 2019
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RIESGO
abrir
GitHub PoC
webcam bug (python)
CVE-2018-999505 sep 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC4
CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque05 sep 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC132
Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect
CVE-2019-11539HIGHbajo ataqueransomware04 sep 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
GitHub PoC1
jaychouzzk/CVE-2019-0193-exp
CVE-2019-0193HIGHbajo ataque03 sep 2019
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RIESGO
abrir
GitHub PoC2
CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。
CVE-2019-0708CRITICALbajo ataqueransomware03 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
A script to Fuzz and and exploit Apache struts CVE-2017-9805
CVE-2017-9805HIGHbajo ataque02 sep 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
simplified version of https://github.com/shauntdergrigorian/cve-2006-6184
CVE-2006-618401 sep 2019
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir
GitHub PoC1
Simple python script to fuzz site for CVE-2017-9805
CVE-2017-9805HIGHbajo ataque31 ago 2019
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
jason3e7/CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware29 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC52
SSL VPN Rce
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC18
Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC5
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
CVE-2019-11510CRITICALbajo ataqueransomware26 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC3
OpenSSH Username Enumeration - CVE-2016-6210
CVE-2016-6210MEDIUM25 ago 2019
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC11
A collection of tools for the Janus exploit [CVE-2017-13156].
CVE-2017-1315625 ago 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC8
The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029
CVE-2019-1502924 ago 2019
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RIESGO
abrir
GitHub PoC11
The official exploit code for Centreon v19.04 Remote Code Execution CVE-2019-13024
CVE-2019-1302424 ago 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RIESGO
abrir
GitHub PoC5
CVE-2019-15107 webmin python3
CVE-2019-15107CRITICALbajo ataqueransomware23 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC52
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
CVE-2019-2725HIGHbajo ataqueransomware23 ago 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC13
Jboss Java Deserialization RCE (CVE-2017-12149)
CVE-2017-12149CRITICALbajo ataqueransomware22 ago 2019
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
anteriorpágina 418 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.