Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.133exploits catalogados
35.369CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC11
just a python script for cve-2017-12615
CVE-2017-12615HIGHbajo ataqueransomware25 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC
Check for Struts Vulnerability CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware25 sep 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
l0n3rs/CVE-2017-8759
CVE-2017-8759HIGHbajo ataque24 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
l0n3rs/CVE-2017-9798
CVE-2017-979824 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
GitHub PoC18
Blueborne CVE-2017-1000251 PoC for linux machines
CVE-2017-100025123 sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
GitHub PoC112
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
CVE-2017-12615HIGHbajo ataqueransomware23 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC
Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
CVE-2017-9791CRITICALbajo ataque23 sep 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC40
CVE-2017-0785 BlueBorne PoC
CVE-2017-078522 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC
CVE-2017-0785: BlueBorne PoC
CVE-2017-078522 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC463
Blueborne CVE-2017-0785 Android information leak vulnerability
CVE-2017-078520 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC2
CVE-2017-9798
CVE-2017-979820 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
GitHub PoC
CVE-2017-8759
CVE-2017-8759HIGHbajo ataque19 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC2
Two versions of CVE-2017-8759 exploits
CVE-2017-8759HIGHbajo ataque19 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
viethdgit/CVE-2017-0199
CVE-2017-0199HIGHbajo ataqueransomware19 sep 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC3
Checks a shared hosting environment for CVE-2017-9798
CVE-2017-979818 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
GitHub PoC5
Simple C# implementation of CVE-2017-8759
CVE-2017-8759HIGHbajo ataque17 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC11
A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)
CVE-2015-856217 sep 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC
CVE-2017-8759 Remote Code Execution Vulnerability On SOAP WDSL - Microsoft .NET Framework 4.6.2 Microsoft .NET Framework 4.6.1 Microsoft .NET Framework 3.5.1 Microsoft .NET Framework 4.7 Microsoft .NET Framework 4.6 Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 3.5
CVE-2017-8759HIGHbajo ataque14 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC312
Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE. It could generate a malicious RTF file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
CVE-2017-8759HIGHbajo ataque14 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC1
CVE-2017-8759 Research
CVE-2017-8759HIGHbajo ataque13 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC94
NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements
CVE-2017-8759HIGHbajo ataque13 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
tahisaad6/CVE-2017-8759-Exploit-sample2
CVE-2017-8759HIGHbajo ataque13 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC176
CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
CVE-2017-8759HIGHbajo ataque13 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC255
Running CVE-2017-8759 exploit sample.
CVE-2017-8759HIGHbajo ataque13 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC5
An exploit for Apache Struts CVE-2017-9805
CVE-2017-9805HIGHbajo ataque10 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC247
An exploit for Apache Struts CVE-2017-9805
CVE-2017-9805HIGHbajo ataque09 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC37
A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)
CVE-2017-1261108 sep 2017
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir
GitHub PoC3
cve -2017-9805
CVE-2017-9805HIGHbajo ataque07 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC60
CVE 2017-9805
CVE-2017-9805HIGHbajo ataque06 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
siling2017/CVE-2017-1000117
CVE-2017-100011704 sep 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
anteriorpágina 452 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.