Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.014 exploits
GitHub PoC1
Simple Bash shell quick fix CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque14 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏
CVE-2019-0708CRITICALbajo ataqueransomware13 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC14
PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.
CVE-2019-10149CRITICALbajo ataque13 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
蓝屏poc
CVE-2019-0708CRITICALbajo ataqueransomware13 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RIESGO
abrir
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RIESGO
abrir
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC7
LPE Exploit For CVE-2019-12181 (Serv-U FTP 15.1.6)
CVE-2019-1218112 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
GitHub PoC14
simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.
CVE-2019-10149CRITICALbajo ataque12 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
CVE-2019-0708-Msf-验证
CVE-2019-0708CRITICALbajo ataqueransomware12 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
CVE-2019-0708-RCE
CVE-2019-0708CRITICALbajo ataqueransomware12 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC2
welove88888/CVE-2019-2725
CVE-2019-2725HIGHbajo ataqueransomware11 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC58
A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.
CVE-2019-0841HIGHbajo ataqueransomware11 jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC13
CVE-2019-0708批量检测
CVE-2019-0708CRITICALbajo ataqueransomware11 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
exploit tool of CVE-2018-11564
CVE-2018-1156410 jun 2019
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RIESGO
abrir
GitHub PoC22
quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos
CVE-2019-10149CRITICALbajo ataque10 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC2
POC of CVE-2017-5487 + tool
CVE-2017-548710 jun 2019
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC1
exploit tool of CVE-2018-10118
CVE-2018-1011810 jun 2019
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir
GitHub PoC1
POC of CVE-2018-8718 + tool
CVE-2018-871810 jun 2019
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir
GitHub PoC118
CVE-2019-0859 1day Exploit
CVE-2019-0859HIGHbajo ataque07 jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir
GitHub PoC9
Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)
CVE-2019-1273506 jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
GitHub PoC
799600966/CVE-2018-17456
CVE-2018-1745605 jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
GitHub PoC
tarantula-team/CVE-2019-12543
CVE-2019-1254304 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceReques
23RIESGO
abrir
GitHub PoC
loudong
CVE-2015-754704 jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC
tarantula-team/CVE-2019-12538
CVE-2019-1253804 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RIESGO
abrir
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RIESGO
abrir
GitHub PoC
tarantula-team/CVE-2019-12542
CVE-2019-1254204 jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RIESGO
abrir
GitHub PoC27
Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support
CVE-2019-0708CRITICALbajo ataqueransomware03 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC37
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
CVE-2019-1069HIGHbajo ataqueransomware03 jun 2019
Task Scheduler Elevation of Privilege Vulnerability
71RIESGO
abrir
anteriorpágina 422 / 468siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.