Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.090 exploits
GitHub PoC1
xssfile/CVE-2017-8464-EXP
CVE-2017-8464HIGHbajo ataque20 abr 2018
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC
CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial
CVE-2018-774720 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RIESGO
abrir
GitHub PoC
mudhappy/Wordpress-Hack-CVE-2018-6389
CVE-2018-638920 abr 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
shaoshore/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque20 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC2
Shadowshusky/CVE-2018-2628all
CVE-2018-2628CRITICALbajo ataque20 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC1
CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque19 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC11
Exploit for CVE-2018-7600.. called drupalgeddon2,
CVE-2018-7600CRITICALbajo ataqueransomware19 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
9uest/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque19 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC119
macOS 10.13.3 (17D47) Safari Wasm Exploit
CVE-2018-412119 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir
GitHub PoC15
WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC2
zjxzjx/CVE-2018-2628-detect
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC14
jiansiting/weblogic-cve-2018-2628
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC20
CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC1
CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC78
CVE-2018-2628 & CVE-2018-2893
CVE-2018-2628CRITICALbajo ataque18 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC141
Exploit for Drupal 7 <= 7.57 CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware17 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC24
POC for CVE-2018-1273
CVE-2018-1273CRITICALbajo ataqueransomware17 abr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir
GitHub PoC1
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
CVE-2017-804616 abr 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
GitHub PoC71
CVE-2018-7600 - Drupal 7.x RCE
CVE-2018-7600CRITICALbajo ataqueransomware16 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC3
Tool to check for CVE-2018-7600 vulnerability on several URLS
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC7
Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC4
Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC41
CVE-2018-6546-Exploit
CVE-2018-654615 abr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir
GitHub PoC5
MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC7
Drupal 0day Remote PHP Code Execution (Perl)
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC4
PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC3
CVE-2018-7600 (Drupal)
CVE-2018-7600CRITICALbajo ataqueransomware13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC10
Environment for CVE-2018-1273 (Spring Data Commons)
CVE-2018-1273CRITICALbajo ataqueransomware13 abr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir
GitHub PoC600
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
Example exploit for CVE-2016-5195
CVE-2016-5195HIGHbajo ataque11 abr 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
anteriorpágina 444 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.