Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.313 exploits
GitHub PoC★ 17
CVE-2024-38077: Remote Code Execution Vulnerability in Windows Remote Desktop Licensing Service
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 27
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RIESGO
abrir ↗GitHub PoC★ 44
Proof of Concept Exploit for CVE-2024-9464
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
70RIESGO
abrir ↗GitHub PoC★ 3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir ↗Metasploit600
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RIESGO
abrir ↗VulnCheck XDB
initial-access
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RIESGO
abrir ↗VulnCheck XDB
infoleak
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RIESGO
abrir ↗GitHub PoC★ 31
Proof of Concept Exploit for CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RIESGO
abrir ↗VulnCheck XDB
infoleak
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RIESGO
abrir ↗GitHub PoC★ 1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC★ 1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC
wargame, CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗GitHub PoC
TeamCity server scanner to detect CVE-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC★ 1
Agilevatester/FlaskCache_CVE-2021-33026_POC
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RIESGO
abrir ↗GitHub PoC
Apache CouchDB 3.2.1 - Remote Code Execution (RCE) Checker
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir ↗Metasploit600
Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Se
65RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗VulnCheck XDB
infoleak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗VulnCheck XDB
infoleak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗VulnCheck XDB
infoleak
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RIESGO
abrir ↗GitHub PoC★ 83
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.