Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.060exploits catalogados
35.302CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC1
linux kernel exploit
CVE-2017-512331 oct 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
GitHub PoC
This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.
CVE-2017-5638CRITICALbajo ataqueransomware30 oct 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
skyformat99/dnsmasq-2.4.1-fix-CVE-2017-14491
CVE-2017-1449130 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
GitHub PoC2
This exploit was written to study some concepts, enjoy!
CVE-2010-422128 oct 2017
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir
GitHub PoC1
dewankpant/CVE-2017-16567
CVE-2017-1656724 oct 2017
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RIESGO
abrir
GitHub PoC
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548722 oct 2017
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC1
Dirty COW (CVE-2016-5195) Testing
CVE-2016-5195HIGHbajo ataque19 oct 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware19 oct 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
PHPMailer < 5.2.18 Remote Code Execution
CVE-2016-1003417 oct 2017
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir
GitHub PoC
A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.
CVE-2014-6271CRITICALbajo ataque17 oct 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
CVE-2010-3332 Oracle Padding Vulnerability in Microsoft ASP.NET
CVE-2010-333211 oct 2017
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RIESGO
abrir
GitHub PoC1
Exploit Safari CVE-2017-7089
CVE-2017-708911 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
GitHub PoC1
Apache HTTP Server 2.4.23 vulnerability study (CVE-2016-8740)
CVE-2016-874011 oct 2017
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RIESGO
abrir
GitHub PoC1
Ready to use, weaponized dirtycow (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque11 oct 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC138
Blueborne CVE-2017-0781 Android heap overflow vulnerability
CVE-2017-078109 oct 2017
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
GitHub PoC27
CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.
CVE-2017-1386807 oct 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
GitHub PoC53
Exploits for the win32kfull!bFill vulnerability on Win10 x64 RS2 using Bitmap or Palette techniques
CVE-2016-3309HIGHbajo ataqueransomware06 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
GitHub PoC5
CVE-2017-12617 and CVE-2017-12615 for tomcat server
CVE-2017-12615HIGHbajo ataqueransomware06 oct 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC399
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
CVE-2017-12617HIGHbajo ataque05 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC31
Scan/Exploit Blueborne CVE-2017-0785
CVE-2017-078504 oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC
Usbhijacking | CVE-2017-8464
CVE-2017-8464HIGHbajo ataque03 oct 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC63
Webkit uxss exploit (CVE-2017-7089)
CVE-2017-708903 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
GitHub PoC3
this script is used for hack bluetooth devices CVE 2017 0785 which was done by ARMIS This File is password protected for password contact atusha@gmail.comr
CVE-2017-078502 oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC3
First script, pgp-cgi-cve-2012-1823 BASH script
CVE-2012-1823CRITICALbajo ataque01 oct 2017
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC
billa3283/CVE-2017-0213
CVE-2017-0213HIGHbajo ataqueransomware01 oct 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
GitHub PoC5
own2pwn/blueborne-CVE-2017-1000251-POC
CVE-2017-100025101 oct 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
GitHub PoC2
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804601 oct 2017
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
GitHub PoC
CVE-2017-12943
CVE-2017-1294329 sep 2017
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RIESGO
abrir
GitHub PoC
clone
CVE-2017-100025128 sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
GitHub PoC19
OptionsBleed (CVE-2017-9798) PoC / Scanner
CVE-2017-979827 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
anteriorpágina 451 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.