Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
14.080 exploits
GitHub PoC110
cve-2018-10933 libssh authentication bypass
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC10
Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC1
Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067
CVE-2008-4250CRITICALbajo ataque18 oct 2018
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC1
likekabin/CVE-2018-10933-libSSH-Authentication-Bypass
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC1
Exploit adapted for a specific PoC on Ubuntu 16.04.01
CVE-2017-1699518 oct 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC14
Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred without a problem. The server expects the message SSH2_MSG_USERAUTH_REQUEST to start the authentication procedure, but by skipping it an attacker can log in without showing any credentials.
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC498
Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC2
Metasploit module for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware17 oct 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC126
CVE-2018-10933 very simple POC
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
CVE-2018-10933 sshlib user authentication attack - docker lab, test and exploit
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC9
Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)
CVE-2017-1000486CRITICALbajo ataque17 oct 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC235
Script to identify hosts vulnerable to CVE-2018-10933
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC61
PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509
CVE-2018-1650915 oct 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC15
Automated version of CVE-2018-14847 (MikroTik Exploit)
CVE-2018-14847CRITICALbajo ataque13 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC8
proof-of-concept (PoC) for linux dists based on Debian, CentOS and RedHat - exploit 1
CVE-2018-14634HIGHbajo ataque08 oct 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RIESGO
abrir
GitHub PoC
OpenSSH < 7.7 User Enumeration CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM08 oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
Metasploit module for CVE-2016-1555
CVE-2016-1555CRITICALbajo ataque06 oct 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RIESGO
abrir
GitHub PoC2
webr0ck/poc-cve-2018-1273
CVE-2018-1273CRITICALbajo ataqueransomware05 oct 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir
GitHub PoC10
An exploitation tool to extract passwords using CVE-2015-5995.
CVE-2015-599504 oct 2018
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RIESGO
abrir
GitHub PoC116
Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473
CVE-2018-15473MEDIUM03 oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
GitHub PoC4
MASS Exploiter
CVE-2018-7600CRITICALbajo ataqueransomware02 oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
likekabin/vmacache_CVE-2018-17182
CVE-2018-1718201 oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC
likekabin/CVE-2018-17182
CVE-2018-1718201 oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC130
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
CVE-2018-1718229 sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC20
Gain root privilege by exploiting CVE-2014-3153 vulnerability
CVE-2014-3153HIGHbajo ataque27 sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC
Make CVE-2007-4607 exploitable again!
CVE-2007-460727 sep 2018
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RIESGO
abrir
GitHub PoC
bkhablenko/CVE-2017-8046
CVE-2017-804626 sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
GitHub PoC1
cscli/CVE-2017-5223
CVE-2017-522326 sep 2018
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RIESGO
abrir
GitHub PoC112
DVR-Exploiter a Bash Script Program Exploit The DVR's Based on CVE-2018-9995
CVE-2018-999523 sep 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
anteriorpágina 438 / 470siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.