Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
13.654 exploits
GitHub PoC★ 17
Progress OpenEdge Authentication Bypass
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
48RIESGO
abrir ↗GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗GitHub PoC★ 37
Exploit for CVE-2024-27198 - TeamCity Server
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC★ 43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC★ 4
A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal
Grafana path traversal
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2024-1071 with Docker
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗GitHub PoC★ 6
Three go-exploits exploiting CVE-2023-22527 to execute arbitrary code in memory
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗GitHub PoC★ 36
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 1
This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗GitHub PoC
RxRCoder/CVE-2023-2437
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RIESGO
abrir ↗GitHub PoC★ 2
PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 2
abian2/CVE-2024-23652
BuildKit possible host system access from mount stub cleaner
48RIESGO
abrir ↗GitHub PoC★ 3
(Mirorring)
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗GitHub PoC
letsr00t/CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗GitHub PoC★ 2
dshabani96/CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 107
Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗GitHub PoC
J3Ss0u/CVE-2023-41993
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RIESGO
abrir ↗GitHub PoC★ 6
CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir ↗GitHub PoC★ 2
jakabakos/CVE-2023-39362-cacti-snmp-command-injection-poc
Authenticated command injection in SNMP options of a Device
63RIESGO
abrir ↗GitHub PoC
letsr00t/CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir ↗GitHub PoC
G01d3nW01f/CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir ↗GitHub PoC★ 8
Ultimate Member Unauthorized Database Access / SQLi
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RIESGO
abrir ↗GitHub PoC
A Craft CMS vulnerability that allows Remote Code Execution (RCE).
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir ↗GitHub PoC★ 40
confluence CVE-2023-22527 漏洞利用工具,支持冰蝎/哥斯拉内存马注入,支持设置 http 代理
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗GitHub PoC
shenhav12/CVE-2024-25169-Mezzanine-v6.0.0
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque
48RIESGO
abrir ↗GitHub PoC
CVE-2024-21887 Exploitation with Ngrok Reverse Shell
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RIESGO
abrir ↗GitHub PoC★ 1
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.