Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
79.596 exploits
GitHub PoC
1-day
CVE-2018-1745621 oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
GitHub PoC22
libssh CVE-2018-10933
CVE-2018-10933CRITICAL20 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
Variant of hackerhouse-opensource/cve-2018-10933
CVE-2018-10933CRITICAL20 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Exploit-DBVexDay Proof
LibSSH 0.7.6 / 0.8.4 - Unauthorized Access
CVE-2018-10933CRITICALremotelinux20 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC11
LibSSH Authentication Bypass Exploit using RCE
CVE-2018-10933CRITICAL20 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
pghook/CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL20 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC110
cve-2018-10933 libssh authentication bypass
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
likekabin/CVE-2018-10933_ssh
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Metasploit300
LibreOffice Macro Code Execution
CVE-2018-16858HIGH18 oct 2018
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
GitHub PoC1
Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067
CVE-2008-4250CRITICALbajo ataque18 oct 2018
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC10
Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC1
Exploit adapted for a specific PoC on Ubuntu 16.04.01
CVE-2017-1699518 oct 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DB
libSSH - Authentication Bypass
CVE-2018-10933CRITICALremotelinux18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
cve-2018/cve-2018-10933
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC1
likekabin/CVE-2018-10933-libSSH-Authentication-Bypass
CVE-2018-10933CRITICAL18 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC497
Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
CVE-2018-10933 sshlib user authentication attack - docker lab, test and exploit
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Exploit-DB
TP-Link TL-SC3130 1.6.18 - RTSP Stream Disclosure
CVE-2018-18428webappshardware17 oct 2018
TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg
28RIESGO
abrir
GitHub PoC235
Script to identify hosts vulnerable to CVE-2018-10933
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC14
Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred without a problem. The server expects the message SSH2_MSG_USERAUTH_REQUEST to start the authentication procedure, but by skipping it an attacker can log in without showing any credentials.
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Exploit-DB
BigTree CMS 4.2.23 - Cross-Site Scripting
CVE-2018-18308webappsphp17 oct 2018
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (ak
23RIESGO
abrir
GitHub PoC126
CVE-2018-10933 very simple POC
CVE-2018-10933CRITICAL17 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC2
Metasploit module for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware17 oct 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC9
Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)
CVE-2017-1000486CRITICALbajo ataque17 oct 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque17 oct 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware17 oct 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-1000364localsolaris16 oct 2018
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'FSCTL_FIND_FILES_BY_SID' Information Disclosure
CVE-2018-8411doswindows16 oct 2018
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln
23RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-3630localsolaris16 oct 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-3631localsolaris16 oct 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
anteriorpágina 873 / 2654siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.