Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8617Nuclei 4257Metasploit 3474✓ solo verificadosrecientespopularesriesgo
14.119 exploits
GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗GitHub PoC★ 11
CVE-2015-3073 PoC
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir ↗GitHub PoC★ 11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC★ 1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC★ 12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗GitHub PoC★ 3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC★ 1
drone789/CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗GitHub PoC★ 1
Just an attempt to adapt for Note 4, I do not know what I am doing.
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir ↗GitHub PoC★ 2
An implementation of the CVE-2015-2153 exploit.
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir ↗GitHub PoC
Windows 2k3 tcpip.sys Privilege Escalation
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir ↗GitHub PoC★ 1
PoC exploit for CVE-2015-5477 in php
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 3
PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir ↗GitHub PoC★ 24
CVE-2014-4322 Exploit
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2015-4495 / mfsa2015-78
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RIESGO
abrir ↗GitHub PoC★ 1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 1
Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 14
PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 3
A little Python tool for exploiting CVE-2015-1560 and CVE-2015-1561. Quick'n'dirty. Real dirty.
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir ↗GitHub PoC★ 64
PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 11
jvazquez-r7/CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗GitHub PoC★ 15
Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 22
Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 6
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 1
This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC
reading course
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC
redhatkaty/-cve-2010-3904-report
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir ↗GitHub PoC
marstornado/cve-2014-0160-Yunfeng-Jiang
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.