Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
14.112 exploits
GitHub PoC
CVE-2015-8562 Exploit in bash
CVE-2015-856208 feb 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC41
Trigger and exploit code for CVE-2014-4113
CVE-2014-4113HIGHbajo ataque07 feb 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
GitHub PoC30
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
GitHub PoC5
A testbed for CVE-2016-0728, a refcount leak/overflow bug in Linux
CVE-2016-072828 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC10
forced-request/rails-rce-cve-2016-0752
CVE-2016-0752HIGHbajo ataque26 ene 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
GitHub PoC
googleweb/CVE-2016-0728
CVE-2016-072823 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC22
nardholio/cve-2016-0728
CVE-2016-072822 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC5
Exploit CVE-2014-4113
CVE-2014-4113HIGHbajo ataque22 ene 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
GitHub PoC3
CVE-2016-0728 Linux Kernel Vulnerability
CVE-2016-072820 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC1
idl3r/cve-2016-0728
CVE-2016-072819 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC67
PoC for CVE-2015-6086
CVE-2015-608618 ene 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RIESGO
abrir
GitHub PoC2
cinno/CVE-2015-7755-POC
CVE-2015-7755CRITICALbajo ataque09 ene 2016
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir
GitHub PoC2
A proof of concept for Joomla's CVE-2015-8562 vulnerability
CVE-2015-856204 ene 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC8
All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.
CVE-2015-856204 ene 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC3
ockeghem/CVE-2015-6835-checker
CVE-2015-683519 dic 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir
GitHub PoC105
Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS
CVE-2015-7755CRITICALbajo ataque18 dic 2015
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir
GitHub PoC3
Crash PoC
CVE-2015-808809 dic 2015
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RIESGO
abrir
GitHub PoC17
Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another Stagefright vulnerability, the integer overflow (CVE-2015-3864).
CVE-2015-386408 dic 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
GitHub PoC5
Estudo e apresentação do bug CVE-2014-4943 para a disciplina MAC0448
CVE-2014-494322 nov 2015
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir
GitHub PoC5
My exploit for kernel exploitation
CVE-2014-3153HIGHbajo ataque08 nov 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC1
PoC code for vBulletin PreAuth vulnerability
CVE-2015-780806 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir
GitHub PoC1
Joomla! 3.2 to 3.4.4 - SQL Injection (CVE-2015-7297, CVE-2015-7857, and CVE-2015-7858)
CVE-2015-729702 nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
GitHub PoC23
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
CVE-2015-1641HIGHbajo ataque27 oct 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp
93RIESGO
abrir
GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
CVE-2014-0160HIGHbajo ataque23 oct 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
CVE-2015-1635CRITICALbajo ataque14 oct 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
CVE-2014-7169CRITICALbajo ataque30 sep 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
GitHub PoC11
CVE-2015-3073 PoC
CVE-2015-307327 sep 2015
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
GitHub PoC11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque24 sep 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
CVE-2015-5119HIGHbajo ataque10 sep 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
GitHub PoC1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153810 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
anteriorpágina 464 / 471siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.