Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.107 exploits
GitHub PoC
CVE-2019-5736
CVE-2019-573612 may 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
Lumindu/CVE-2017-16995-Linux-Kernel---BPF-Sign-Extension-Local-Privilege-Escalation-
CVE-2017-1699512 may 2020
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC
This is an individual assignment for secure network programming
CVE-2014-6271CRITICALbajo ataque12 may 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
BimsaraMalinda/Linux-Kernel-4.4.0-Ubuntu---DCCP-Double-Free-Privilege-Escalation-CVE-2017-6074
CVE-2017-607412 may 2020
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir
GitHub PoC
Dilith006/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque12 may 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC3
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153812 may 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC
CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability
CVE-2017-8759HIGHbajo ataque12 may 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
CVE-2017-8759 || report related with execute code vulnerability
CVE-2017-8759HIGHbajo ataque12 may 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
sachinthaBS/Spectre-Vulnerability-CVE-2017-5753-
CVE-2017-5753MEDIUM12 may 2020
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
lalishasanduwara/CVE-2018-10933
CVE-2018-10933CRITICAL12 may 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
Document on Linux Kernal Vulnerability CVE-2016-0728 and Exploitation
CVE-2016-072812 may 2020
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC
dinidhu96/IT19013756_-CVE-2016-4971-
CVE-2016-497112 may 2020
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
GitHub PoC
CVE-2020-1938 exploit
CVE-2020-1938CRITICALbajo ataque12 may 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Glibc-Vulnerability-Exploit-CVE-2015-7547
CVE-2015-754712 may 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC
This is about CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque12 may 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Exploit code for CVE-2015-5477 POC
CVE-2015-547711 may 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Metasploit600
Wordpress Drag and Drop Multi File Uploader RCE
CVE-2020-1280011 may 2020
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa
60RIESGO
abrir
GitHub PoC
Sudo Security Policy bypass Vulnerability
CVE-2019-1428711 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC
shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-
CVE-2016-5195HIGHbajo ataque11 may 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
CVE-2020-12608localwindows11 may 2020
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RIESGO
abrir
GitHub PoC
Documentation for Sudo Security Bypass - CVE 2019-14287
CVE-2019-1428711 may 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
CVE-2015-153811 may 2020
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC1
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287
CVE-2019-13272HIGHbajo ataque11 may 2020
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-547711 may 2020
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1040MEDIUM11 may 2020
Windows NTLM Tampering Vulnerability
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2883CRITICALbajo ataque10 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC10
A Python script to exploit CVE-2020-8816, a remote code execution vulnerability on the Pi-hole
CVE-2020-8816CRITICALbajo ataque10 may 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8816CRITICALbajo ataque10 may 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
CVE-2020-11108webappslinux10 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
GitHub PoC
A remote code execution flaw was found in Samba. A malicious authenticated samba client, having write access to the samba share, could use this flaw to execute arbitrary code as root.
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2020
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
anteriorpágina 772 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.