Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
79.107 exploits
VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir ↗Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RIESGO
abrir ↗Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RIESGO
abrir ↗GitHub PoC★ 1
CVE-2019-5096(UAF in upload handler) exploit cause Denial of Service
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
60RIESGO
abrir ↗Exploit-DB
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗Metasploit600
SharePoint Workflows XOML Injection
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir ↗Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RIESGO
abrir ↗GitHub PoC★ 132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RIESGO
abrir ↗Exploit-DB
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RIESGO
abrir ↗GitHub PoC★ 6
CVE-2020-1938(GhostCat) clean and readable code version
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗GitHub PoC★ 354
Exploit and detect tools for CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 11
HumanSecurity/CVE-2019-18426
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RIESGO
abrir ↗VulnCheck XDB
client-side
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RIESGO
abrir ↗GitHub PoC★ 1
I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 37
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir ↗Exploit-DB
qdPM < 9.1 - Remote Code Execution
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir ↗GitHub PoC★ 337
Weblogic IIOP CVE-2020-2551
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 5
Disclosure report of CVE-2020-9038
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RIESGO
abrir ↗GitHub PoC★ 144
CVE-2020-0688_EXP Auto trigger payload & encrypt method
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 328
cve-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 2
Exchange Scanner CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir ↗GitHub PoC★ 66
CVE-2020-0688 - Exchange
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗GitHub PoC★ 1
Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.