Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
14.119 exploits
GitHub PoC2
Technicolor TC7200 - Credentials Disclosure CVE : CVE-2014-1677
CVE-2014-167731 jul 2014
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
28RIESGO
abrir
GitHub PoC124
CVE-2014-3153 aka towelroot
CVE-2014-3153HIGHbajo ataque24 jul 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC6
POC Code to exploite CVE-2014-3120
CVE-2014-3120HIGHbajo ataque07 jul 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
GitHub PoC4
Exploit for cve-2012-3137 Oracle challenge
CVE-2012-313718 jun 2014
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all
35RIESGO
abrir
GitHub PoC1
struts1 CVE-2014-0114 classLoader manipulation vulnerability patch
CVE-2014-011410 jun 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
GitHub PoC12
A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team
CVE-2014-011422 may 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
GitHub PoC
Demonstration of CVE-2014-3120
CVE-2014-3120HIGHbajo ataque13 may 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
GitHub PoC
SunRain/CVE-2014-0196
CVE-2014-0196MEDIUMbajo ataque13 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
GitHub PoC18
cve-2014-0130 rails directory traversal vuln
CVE-2014-0130HIGHbajo ataque08 may 2014
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in
83RIESGO
abrir
GitHub PoC15
CVE-2014-0160 (Heartbeat Buffer over-read bug)
CVE-2014-0160HIGHbajo ataque03 may 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC18
Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque01 may 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
CVE-2014-0094 test program for struts1
CVE-2014-009427 abr 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
GitHub PoC4
openssl Heartbleed bug(CVE-2014-0160) check for Node.js
CVE-2014-0160HIGHbajo ataque19 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC3
A checker (site and tool) for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC98
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
A checker (site and tool) for CVE-2014-0160:
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC5
POC for CVE-2014-0160 (Heartbleed) for DTLS
CVE-2014-0160HIGHbajo ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC6
Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160
CVE-2014-0160HIGHbajo ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.
CVE-2014-0160HIGHbajo ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2014-0160 scanner
CVE-2014-0160HIGHbajo ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
Test CIDR blocks for CVE-2014-0160/Heartbleed
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
ice-security88/CVE-2014-0160
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC8
Heartbleed variants
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
OpenSSL Heartbleed (CVE-2014-0160) Fix script
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2014-0160 mass test against subdomains
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
A firefox extension and checker for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque09 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
anteriorpágina 469 / 471siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.