Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
14.119 exploits
GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
CVE-2014-0160HIGHbajo ataque23 oct 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
CVE-2015-1635CRITICALbajo ataque14 oct 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
CVE-2014-7169CRITICALbajo ataque30 sep 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
GitHub PoC11
CVE-2015-3073 PoC
CVE-2015-307327 sep 2015
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
GitHub PoC11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque24 sep 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153810 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153810 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
CVE-2015-5119HIGHbajo ataque10 sep 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
GitHub PoC3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153809 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC1
drone789/CVE-2012-1823
CVE-2012-1823CRITICALbajo ataque08 sep 2015
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
Just an attempt to adapt for Note 4, I do not know what I am doing.
CVE-2014-432204 sep 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
GitHub PoC2
An implementation of the CVE-2015-2153 exploit.
CVE-2015-215327 ago 2015
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir
GitHub PoC
Windows 2k3 tcpip.sys Privilege Escalation
CVE-2014-407620 ago 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
GitHub PoC1
PoC exploit for CVE-2015-5477 in php
CVE-2015-547719 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC3
PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)
CVE-2015-386418 ago 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
GitHub PoC24
CVE-2014-4322 Exploit
CVE-2014-432216 ago 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
GitHub PoC1
Exploit for CVE-2015-4495 / mfsa2015-78
CVE-2015-4495HIGHbajo ataque10 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RIESGO
abrir
GitHub PoC1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
CVE-2015-547709 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC1
Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software
CVE-2015-547704 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC14
PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability
CVE-2015-547701 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC3
A little Python tool for exploiting CVE-2015-1560 and CVE-2015-1561. Quick'n'dirty. Real dirty.
CVE-2015-156031 jul 2015
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir
GitHub PoC64
PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure
CVE-2015-547731 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC11
jvazquez-r7/CVE-2015-5119
CVE-2015-5119HIGHbajo ataque29 jul 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
GitHub PoC15
Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed
CVE-2014-0160HIGHbajo ataque12 jul 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC22
Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock
CVE-2014-6271CRITICALbajo ataque11 jul 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC6
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).
CVE-2014-6271CRITICALbajo ataque26 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque17 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
reading course
CVE-2014-6271CRITICALbajo ataque10 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
redhatkaty/-cve-2010-3904-report
CVE-2010-3904HIGHbajo ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
GitHub PoC
marstornado/cve-2014-0160-Yunfeng-Jiang
CVE-2014-0160HIGHbajo ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
anteriorpágina 465 / 471siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.