Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8607Nuclei 4255Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.058 exploits
GitHub PoC
Exploit for CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RIESGO
abrir ↗GitHub PoC
A PoC for CVE-2024-27198 written in Go
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 39
hd3s5aa/CVE-2023-21674
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RIESGO
abrir ↗VulnCheck XDB
local
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗GitHub PoC★ 3
Brute Hikvision CAMS with CVE-2021-36260 Exploit
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗GitHub PoC★ 17
Progress OpenEdge Authentication Bypass
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
48RIESGO
abrir ↗GitHub PoC★ 4
PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RIESGO
abrir ↗GitHub PoC★ 157
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC★ 37
Exploit for CVE-2024-27198 - TeamCity Server
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗Metasploit600
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir ↗Metasploit600
Judge0 sandbox escape
Judge0 vulnerable to Sandbox Escape via Symbolic Link
43RIESGO
abrir ↗Metasploit600
pgAdmin Session Deserialization RCE
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
65RIESGO
abrir ↗Metasploit600
Judge0 sandbox escape
Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
43RIESGO
abrir ↗Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 4
A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal
Grafana path traversal
100RIESGO
abrir ↗GitHub PoC★ 36
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir ↗GitHub PoC★ 6
Three go-exploits exploiting CVE-2023-22527 to execute arbitrary code in memory
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.