Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
14.119 exploits
GitHub PoC
1-day
CVE-2018-1745621 out 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISCO
abrir
GitHub PoC3
a python script to exploit libssh authentication vulnerability
CVE-2018-10933CRITICAL21 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC2
CVE-2018-10933
CVE-2018-10933CRITICAL21 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC22
libssh CVE-2018-10933
CVE-2018-10933CRITICAL20 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
Variant of hackerhouse-opensource/cve-2018-10933
CVE-2018-10933CRITICAL20 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC11
LibSSH Authentication Bypass Exploit using RCE
CVE-2018-10933CRITICAL20 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
pghook/CVE-2018-10933_Scanner
CVE-2018-10933CRITICAL20 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC110
cve-2018-10933 libssh authentication bypass
CVE-2018-10933CRITICAL18 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC1
likekabin/CVE-2018-10933-libSSH-Authentication-Bypass
CVE-2018-10933CRITICAL18 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC10
Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)
CVE-2018-10933CRITICAL18 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC1
Scripts to analyze conflicker worm which exploits famous netapi vulnerability (CVE-2008-4250) i.e MS08-067
CVE-2008-4250CRITICALsob ataque18 out 2018
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
GitHub PoC1
Exploit adapted for a specific PoC on Ubuntu 16.04.01
CVE-2017-1699518 out 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISCO
abrir
GitHub PoC
cve-2018/cve-2018-10933
CVE-2018-10933CRITICAL18 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC
likekabin/CVE-2018-10933_ssh
CVE-2018-10933CRITICAL18 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC235
Script to identify hosts vulnerable to CVE-2018-10933
CVE-2018-10933CRITICAL17 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC2
Metasploit module for CVE-2018-4878
CVE-2018-4878HIGHsob ataqueransomware17 out 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
GitHub PoC126
CVE-2018-10933 very simple POC
CVE-2018-10933CRITICAL17 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC14
Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred without a problem. The server expects the message SSH2_MSG_USERAUTH_REQUEST to start the authentication procedure, but by skipping it an attacker can log in without showing any credentials.
CVE-2018-10933CRITICAL17 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC9
Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)
CVE-2017-1000486CRITICALsob ataque17 out 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISCO
abrir
GitHub PoC
CVE-2018-10933 sshlib user authentication attack - docker lab, test and exploit
CVE-2018-10933CRITICAL17 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC498
Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)
CVE-2018-10933CRITICAL17 out 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISCO
abrir
GitHub PoC61
PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509
CVE-2018-1650915 out 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISCO
abrir
GitHub PoC15
Automated version of CVE-2018-14847 (MikroTik Exploit)
CVE-2018-14847CRITICALsob ataque13 out 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
GitHub PoC
OpenSSH < 7.7 User Enumeration CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM08 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC8
proof-of-concept (PoC) for linux dists based on Debian, CentOS and RedHat - exploit 1
CVE-2018-14634HIGHsob ataque08 out 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RISCO
abrir
GitHub PoC2
Metasploit module for CVE-2016-1555
CVE-2016-1555CRITICALsob ataque06 out 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RISCO
abrir
GitHub PoC2
webr0ck/poc-cve-2018-1273
CVE-2018-1273CRITICALsob ataqueransomware05 out 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISCO
abrir
GitHub PoC10
An exploitation tool to extract passwords using CVE-2015-5995.
CVE-2015-599504 out 2018
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RISCO
abrir
GitHub PoC116
Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473
CVE-2018-15473MEDIUM03 out 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISCO
abrir
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 out 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISCO
abrir
anteriorpágina 439 / 471próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.