Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.226exploits catalogados
36.422CVEs con explotación pública
24.695probados en laboratorio
79.108 exploits
VulnCheck XDB
local
CVE-2019-8605HIGHbajo ataque20 ene 2020
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2551CRITICALbajo ataque19 ene 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC211
how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP
CVE-2020-2551CRITICALbajo ataque19 ene 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC
Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic
CVE-2020-0601HIGHbajo ataque19 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC3
CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections.
CVE-2020-0601HIGHbajo ataque19 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHbajo ataque19 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601
CVE-2020-0601HIGHbajo ataque18 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC4
CVE-2019-19844 Docker Edition
CVE-2019-1984418 ene 2020
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
GitHub PoC80
Weblogic RCE with IIOP
CVE-2020-2551CRITICALbajo ataque18 ene 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
Exploit-DBVexDay Proof
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
CVE-2019-15742localwindows17 ene 2020
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RIESGO
abrir
GitHub PoC1
CVE-2019-19781 Attack Triage Script
CVE-2019-19781CRITICALbajo ataqueransomware17 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
C++ based utility to check if certificates are trying to exploit CVE-2020-0601
CVE-2020-0601HIGHbajo ataque17 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC2
CurveBall CVE exploitation
CVE-2020-0601HIGHbajo ataque17 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
MarkusZehnle/CVE-2020-0601
CVE-2020-0601HIGHbajo ataque17 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
批量概念驗證用
CVE-2019-19781CRITICALbajo ataqueransomware17 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash
CVE-2019-19781CRITICALbajo ataqueransomware17 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC1
Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909
CVE-2020-0601HIGHbajo ataque17 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-19781CRITICALbajo ataqueransomware17 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0601HIGHbajo ataque16 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC66
Proof of Concept for CVE-2020-0601
CVE-2020-0601HIGHbajo ataque16 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DB
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
CVE-2019-19781CRITICALbajo ataqueransomwarewebappsmultiple16 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC1
Curated list of CVE-2020-0601 resources
CVE-2020-0601HIGHbajo ataque16 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC5
😂An awesome curated list of repos for CVE-2020-0601.
CVE-2020-0601HIGHbajo ataque16 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
Exploit-DB
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
CVE-2020-2096webappsjava16 ene 2020
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RIESGO
abrir
Exploit-DB
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
CVE-2019-20204webappsphp16 ene 2020
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn
23RIESGO
abrir
GitHub PoC3
Check ADC for CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware16 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC2
This script checks the Citrix Netscaler if it has been compromised by CVE-2019-19781 attacks and collects all file system information
CVE-2019-19781CRITICALbajo ataqueransomware16 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
Castaldio86/Detect-CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware16 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC2073
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883
CVE-2017-324815 ene 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
GitHub PoC3
Automated forensic script hunting for cve-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware15 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
anteriorpágina 794 / 2637siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.