Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC
TamiiLambrado/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
CVE-2017-5638CRITICALbajo ataqueransomware24 ago 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP. An exception will occur immediatly when opening POC.html in Edge.
CVE-2017-864121 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
GitHub PoC
test for CVE-2017-1000117
CVE-2017-100011721 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC2
CVE-2016-7608: Buffer overflow in IOFireWireFamily.
CVE-2016-760819 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
GitHub PoC2
An EXP could run on Windows x64 against CVE-2008-4654.
CVE-2008-465418 ago 2017
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
GitHub PoC2
GitのCommand Injectionの脆弱性を利用してスクリプトを落として実行する例
CVE-2017-100011718 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
ikmski/CVE-2017-1000117
CVE-2017-100011717 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC4
ieee0824/CVE-2017-1000117
CVE-2017-100011716 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
Experiment of CVE-2017-1000117
CVE-2017-100011716 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
CVE-2017-1000117
CVE-2017-100011716 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
takehaya/CVE-2017-1000117
CVE-2017-100011716 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
CVE-2017-1000117の検証
CVE-2017-100011715 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
shogo82148/Fix-CVE-2017-1000117
CVE-2017-100011715 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC1
sasairc/CVE-2017-1000117_wasawasa
CVE-2017-100011715 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC136
Check Git's vulnerability CVE-2017-1000117
CVE-2017-100011714 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
Xhendos/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware12 ago 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC3
VulApps/CVE-2017-1000117
CVE-2017-100011712 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
test
CVE-2017-100011712 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
thelastbyte/CVE-2017-1000117
CVE-2017-100011712 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC12
poc for cve-2017-10661
CVE-2017-1066111 ago 2017
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RIESGO
abrir
GitHub PoC7
Proof of concept of CVE-2017-1000117
CVE-2017-100011711 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC15
Manouchehri/CVE-2017-1000117
CVE-2017-100011711 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
GitHub PoC
This is an exploit for CVE-2017-7047, Works on 10.3.2 and below.
CVE-2017-704710 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir
GitHub PoC8
this tool can generate a exp for cve-2017-8486, it is developed by python
CVE-2017-8464HIGHbajo ataque07 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC7
Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)
CVE-2017-704705 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir
GitHub PoC3
CVE-2017-2388: Null-pointer dereference in IOFireWireFamily.
CVE-2017-238804 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
GitHub PoC14
CVE-2016-0040 Privilege Escalation Exploit For WMI Receive Notification Vulnerability (x86-64)
CVE-2016-0040HIGHbajo ataque03 ago 2017
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
GitHub PoC67
Support x86 and x64
CVE-2017-8464HIGHbajo ataque02 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC47
Exploit for Jenkins serialization vulnerability - CVE-2016-0792
CVE-2016-079230 jul 2017
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir
GitHub PoC53
Broadpwn bug (CVE-2017-9417)
CVE-2017-941729 jul 2017
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn
35RIESGO
abrir
anteriorpágina 453 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.