Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
14.049 exploits
GitHub PoC
cve-2019-9184
CVE-2019-918415 mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
GitHub PoC
cve-2019-9194
CVE-2019-919415 mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
GitHub PoC1
原创作者:Bearcat@secfree.com
CVE-2017-10271HIGHbajo ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
CVE-2018-113315 mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RIESGO
abrir
GitHub PoC
cve-2018-16283
CVE-2018-1628315 mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RIESGO
abrir
GitHub PoC
The exploit python script for CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware15 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
CVE-2019-6340HIGHbajo ataque12 mar 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
GitHub PoC
AeolusTF/CVE-2018-20250
CVE-2018-20250HIGHbajo ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC7
CVE-2018-20250-WINRAR-ACE Exploit with a UI
CVE-2018-20250HIGHbajo ataqueransomware08 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC209
A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.
CVE-2018-444108 mar 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RIESGO
abrir
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2018-199900206 mar 2019
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RIESGO
abrir
GitHub PoC
Python CVE-2019-1003000 and CVE-2018-1999002 Pre-Auth RCE Jenkins
CVE-2019-100300006 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
GitHub PoC126
ze0r/CVE-2018-8639-exp
CVE-2018-8639HIGHbajo ataqueransomware05 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RIESGO
abrir
GitHub PoC2
Python tool exploiting CVE-2018-20250 found by CheckPoint folks
CVE-2018-20250HIGHbajo ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC1
WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the people didn't update winrar so they are vulnerable in this Absolute Path Traversal bug [CVE-2018-20250]
CVE-2018-20250HIGHbajo ataqueransomware04 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC2
STP5940/CVE-2018-20250
CVE-2018-20250HIGHbajo ataqueransomware28 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC
yyqs2008/CVE-2019-5736-PoC-2
CVE-2019-573628 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC2
Demonstration of the Heartbleed Bug CVE-2014-0160
CVE-2014-0160HIGHbajo ataque27 feb 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
cve-2019-6340
CVE-2019-6340HIGHbajo ataque26 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC12
CVE-2019-6340 POC Drupal rce
CVE-2019-6340HIGHbajo ataque25 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC2
CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples
CVE-2019-6340HIGHbajo ataque25 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC73
A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
CVE-2019-894225 feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
GitHub PoC153
🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻
CVE-2019-7238CRITICALbajo ataque24 feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC21
Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).
CVE-2018-20250HIGHbajo ataqueransomware23 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC42
Environment for CVE-2019-6340 (Drupal)
CVE-2019-6340HIGHbajo ataque23 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC492
exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC30
CVE-2019-6340-Drupal SA-CORE-2019-003
CVE-2019-6340HIGHbajo ataque22 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC26
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC
nmweizi/CVE-2018-20250-poc-winrar
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
anteriorpágina 430 / 469siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.