Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC107
Weblogic 反序列化漏洞(CVE-2018-2628)
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC
cve-2018-2628 反弹shell
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC6
MS Word MS WordPad via IE VBS Engine RCE
CVE-2018-8174HIGHbajo ataqueransomware01 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
My version - CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass on Win7 x64 CVE-2018-6892
CVE-2018-689231 may 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
GitHub PoC
My version - [Win10 x64] CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass CVE-2018-6892
CVE-2018-689231 may 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
GitHub PoC9
Tools to exercise the Linux kernel mitigation for CVE-2018-3639 (aka Variant 4) using the Speculative Store Bypass Disable (SSBD) feature of x86 processors
CVE-2018-3639MEDIUM31 may 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC139
CVE-2018-8174_python
CVE-2018-8174HIGHbajo ataqueransomware30 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC141
编译好的脏牛漏洞(CVE-2016-5195)EXP
CVE-2016-5195HIGHbajo ataque27 may 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC4
Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.
CVE-2018-10562CRITICALbajo ataqueransomware26 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC6
Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit
CVE-2018-806525 may 2018
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir
GitHub PoC
soch4n/CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware25 may 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC6
Detecion for the vulnerability CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque24 may 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC167
CVE-2018-8174 - VBScript memory corruption exploit.
CVE-2018-8174HIGHbajo ataqueransomware22 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
My version - Easy File Sharing Web Server 7.2 - 'UserID' - Win 7 'DEP' bypass
CVE-2018-905920 may 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
GitHub PoC12
CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability
CVE-2018-1131119 may 2018
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
GitHub PoC498
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHbajo ataqueransomware19 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC12
CVE-2018-1111 DynoRoot
CVE-2018-1111HIGH18 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
GitHub PoC163
bigric3/cve-2018-8120
CVE-2018-8120HIGHbajo ataqueransomware17 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC2
Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.
CVE-2018-10562CRITICALbajo ataqueransomware17 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC13
Environment for DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
GitHub PoC5
Windows: heap overflow in jscript.dll in Array.sort
CVE-2017-1190716 may 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
GitHub PoC24
Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.
CVE-2018-10562CRITICALbajo ataqueransomware15 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC
ISC INN 2.x - Command-Line Buffer Overflow
CVE-2001-144214 may 2018
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
23RIESGO
abrir
GitHub PoC423
Arbitrary code execution with kernel privileges using CVE-2018-8897.
CVE-2018-889713 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
GitHub PoC4
The exploitation for CVE-2018-8897
CVE-2018-889713 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
GitHub PoC16
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script
CVE-2017-5638CRITICALbajo ataqueransomware13 may 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier
CVE-2002-099111 may 2018
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RIESGO
abrir
GitHub PoC2
gwolfs/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999511 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
CVE-2002-074011 may 2018
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RIESGO
abrir
GitHub PoC
CVE-2017-7494 C poc
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2018
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
anteriorpágina 442 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.