Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
14.096 exploits
GitHub PoC1
ProFTPd 1.3.5 - File Copy
CVE-2015-330629 jul 2017
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC1
搭建漏洞利用测试环境
CVE-2017-7494CRITICALbajo ataqueransomware28 jul 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC55
CVE-2017-5689 Proof-of-Concept exploit
CVE-2017-5689CRITICALbajo ataque27 jul 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
GitHub PoC66
ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)
CVE-2017-8570HIGHbajo ataque24 jul 2017
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
GitHub PoC3
Exploit created by: R4v3nBl4ck end Pacman
CVE-2017-5638CRITICALbajo ataqueransomware24 jul 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
liusec/WP-CVE-2016-10033
CVE-2016-10033CRITICALbajo ataque22 jul 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC8
CVE-2014-9322 (a.k.a BadIRET) proof of concept for Linux
CVE-2014-932219 jul 2017
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir
GitHub PoC339
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
CVE-2017-0144HIGHbajo ataqueransomware16 jul 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC24
CVE-2014-1303 (WebKit Heap based BOF) proof of concept for Linux
CVE-2014-130307 jul 2017
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir
GitHub PoC27
CVE-2017-9791
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC2
Apache struts struts 2 048, CVE-2017-9791.
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC2
POC for java RMI deserialization vulnerability
CVE-2017-324104 jul 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir
GitHub PoC
VideoLAN VLC media player 0.9.4 Media Player ty.c buffer overflow
CVE-2008-465402 jul 2017
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
GitHub PoC57
CVE-2017-0213 for command line
CVE-2017-0213HIGHbajo ataqueransomware01 jul 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
GitHub PoC
sUbc0ol/CVE-2015-0235
CVE-2015-023530 jun 2017
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC13
sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
sUbc0ol/Microsoft-Word-CVE-2017-0199-
CVE-2017-0199HIGHbajo ataqueransomware30 jun 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC
FreeSSHD Remote Authentication Bypass Vulnerability (freeSSHd 2.1.3)
CVE-2012-606630 jun 2017
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir
GitHub PoC
shaheemirza/CVE-2017-0213-
CVE-2017-0213HIGHbajo ataqueransomware29 jun 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
GitHub PoC1
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque29 jun 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
qwertyuiop12138/CVE-2016-10033
CVE-2016-10033CRITICALbajo ataque28 jun 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-3078
CVE-2017-307826 jun 2017
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Text
35RIESGO
abrir
GitHub PoC
InSpec profile to verify a node is patched and compliant for CVE-2017-8543
CVE-2017-8543CRITICALbajo ataque19 jun 2017
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008
90RIESGO
abrir
GitHub PoC2
os experiment 4 CVE-2016-5195
CVE-2016-5195HIGHbajo ataque16 jun 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
CVE-2017-5638 Test environment
CVE-2017-5638CRITICALbajo ataqueransomware13 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-9430
CVE-2017-943008 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
GitHub PoC1
Struts-RCE CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC6
own implementation of the CVE-2017-1000367 sudo privilege escalation vulnerability in python
CVE-2017-100036708 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
anteriorpágina 454 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.