Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC1
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548717 feb 2018
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC1
Containerized exploitable PhpCollab
CVE-2017-609017 feb 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
GitHub PoC29
CVE-2009-2698 compiled for CentOS 4.8
CVE-2009-269816 feb 2018
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo
23RIESGO
abrir
GitHub PoC
Global Fix for Wordpress CVE-2018-6389
CVE-2018-638915 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC6
Struts02 s2-045 exploit program
CVE-2017-5638CRITICALbajo ataqueransomware15 feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC3
CVE-2015-5374 Denial of Service PoC
CVE-2015-537414 feb 2018
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RIESGO
abrir
GitHub PoC9
ChakraCore exploitation techniques
CVE-2016-719013 feb 2018
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
GitHub PoC86
Aggressor Script to launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware10 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC16
Ruby On Rails unrestricted render() exploit
CVE-2016-209809 feb 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC23
mdsecactivebreach/CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware09 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC2
Metasploit module for WordPress DOS load-scripts.php CVE-2018-638
CVE-2018-638909 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
Aggressor Script to just launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware09 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC6
PHPMailer < 5.2.18 Remote Code Execution Exploit
CVE-2016-10033CRITICALbajo ataque09 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC
Code put together from a few peoples ideas credit given don't use maliciously please
CVE-2017-12617HIGHbajo ataque09 feb 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC8
Exploit for CVE-2017-11826
CVE-2017-11826HIGHbajo ataque09 feb 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RIESGO
abrir
GitHub PoC2
Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224
CVE-2015-322408 feb 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
GitHub PoC57
A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
CVE-2018-010108 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
GitHub PoC31
glibc getcwd() local privilege escalation compiled binaries
CVE-2018-100000107 feb 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
GitHub PoC10
WordPress DoS (CVE-2018-6389)
CVE-2018-638907 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC1
Patch Wordpress DOS breach (CVE-2018-6389) in PHP
CVE-2018-638907 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC14
1337g/CVE-2018-0101-DOS-POC
CVE-2018-010107 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
GitHub PoC18
MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS). This is a directory traversal vulnerability.
CVE-2018-263607 feb 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RIESGO
abrir
GitHub PoC33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
CVE-2017-10271HIGHbajo ataqueransomware07 feb 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC1
To solve CTFS.me problem
CVE-2016-10033CRITICALbajo ataque06 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC1
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
malware del lado del cliente de explotacion de vulnerabilidad de internet explorer 6.0 SP1 en windows xp SP2. No requiere de consentimiento por parte del usuario y no descarga ningun archivo
CVE-2006-477706 feb 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir
GitHub PoC82
CVE-2018-6389 Exploit In WordPress DoS
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC90
Test and exploit for CVE-2017-12542
CVE-2017-1254205 feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
GitHub PoC6
phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)
CVE-2009-1151CRITICALbajo ataque03 feb 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
anteriorpágina 447 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.