Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
79.230 exploits
GitHub PoC★ 56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC★ 167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC★ 5
Instructions for installing a vulnerable version of Exim and its expluatation
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RIESGO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗VulnCheck XDB
infoleak
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir ↗Metasploit400
Nostromo Directory Traversal Remote Command Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗GitHub PoC★ 5
RCE Exploit For CVE-2019-17424 (nipper-ng 0.11.10)
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RIESGO
abrir ↗GitHub PoC★ 9
Metasploit module & Python script for CVE-2019-16405
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RIESGO
abrir ↗GitHub PoC
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RIESGO
abrir ↗GitHub PoC★ 89
kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir ↗GitHub PoC★ 3
Sudo Security Bypass (CVE-2019-14287)
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 6
Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗GitHub PoC
CVE-2012-5960, CVE-2012-5959 Proof of Concept
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗GitHub PoC★ 3
CVE 2019-2215 Android Binder Use After Free
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗Metasploit300
ThinVNC Directory Traversal
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir ↗Metasploit600
Solaris xscreensaver log Privilege Escalation
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir ↗GitHub PoC★ 10
Standalone Python 3 exploit for CVE-2017-17562
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RIESGO
abrir ↗GitHub PoC★ 18
Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 38
This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to successfully exploit the vulnerability.
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.