Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.108exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
79.107 exploits
GitHub PoC★ 1
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油!
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir ↗GitHub PoC★ 3
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗VulnCheck XDB
initial-access
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC★ 196
SQL Server Reporting Services(CVE-2020-0618)中的RCE
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗GitHub PoC★ 2
User Enumeration Proof Of Concept Exploit for CVE-2019-8449
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RIESGO
abrir ↗GitHub PoC★ 1
POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir ↗GitHub PoC
exploit for DNS 4.3
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir ↗Exploit-DB
PANDORAFMS 7.0 - Authenticated Remote Code Execution
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac
28RIESGO
abrir ↗GitHub PoC★ 2
An Python Exploit for Sudo vulnerability CVE-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗GitHub PoC
PoC for CVE-2020-0601 vulnerability (Code Signing)
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir ↗GitHub PoC★ 3
PostgreSQL Remote Code Executuon
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP System Event Utility - Local Privilege Escalation
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir ↗Metasploit600
Service Tracing Privilege Elevation Vulnerability
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
23RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir ↗VulnCheck XDB
initial-access
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗GitHub PoC
N0b1e6/CVE-2018-1335-Python3
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗GitHub PoC★ 336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir ↗Metasploit600
Exchange Control Panel ViewState Deserialization
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir ↗Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RIESGO
abrir ↗Metasploit600
SQL Server Reporting Services (SSRS) ViewState Deserialization
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir ↗GitHub PoC
https://github.com/awakened1712/CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RIESGO
abrir ↗Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.