Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.081exploits catalogados
38.339CVEs com exploração pública
24.695testados em laboratório
82.081 exploits
GitHub PoC
Exploit for CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
CVE-2024-22393CRITICAL08 mar 2024
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISCO
abrir ↗
GitHub PoC★ 3
passwa11/CVE-2024-27198-RCE
CVE-2024-27198CRITICALsob ataqueransomware08 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware08 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALsob ataque07 mar 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2022-1386—07 mar 2024
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISCO
abrir ↗
VulnCheck XDB
local
CVE-2023-21674HIGHsob ataque07 mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC
A PoC for CVE-2024-27198 written in Go
CVE-2024-27198CRITICALsob ataqueransomware07 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware07 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 39
hd3s5aa/CVE-2023-21674
CVE-2023-21674HIGHsob ataque07 mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RISCO
abrir ↗
GitHub PoC★ 4
Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL07 mar 2024
SQLi in TMT's Lockcell
48RISCO
abrir ↗
GitHub PoC★ 3
Brute Hikvision CAMS with CVE-2021-36260 Exploit
CVE-2021-36260CRITICALsob ataque07 mar 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISCO
abrir ↗
GitHub PoC★ 4
PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3
CVE-2024-25832HIGH06 mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27199HIGHsob ataqueransomware06 mar 2024
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 17
Progress OpenEdge Authentication Bypass
CVE-2024-1403CRITICAL06 mar 2024
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
48RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware06 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
CVE-2014-6287CRITICALsob ataque06 mar 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALsob ataque06 mar 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir ↗
GitHub PoC★ 154
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALsob ataqueransomware06 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 37
Exploit for CVE-2024-27198 - TeamCity Server
CVE-2024-27198CRITICALsob ataqueransomware05 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
Metasploit600
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
CVE-2024-2054CRITICAL05 mar 2024
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RISCO
abrir ↗
GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
CVE-2011-2523—05 mar 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir ↗
GitHub PoC★ 43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
CVE-2023-46604CRITICALsob ataqueransomware05 mar 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALsob ataqueransomware05 mar 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware05 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 1
This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)
CVE-2020-0796CRITICALsob ataqueransomware04 mar 2024
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALsob ataqueransomware04 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 34
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALsob ataqueransomware04 mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISCO
abrir ↗
GitHub PoC★ 6
Three go-exploits exploiting CVE-2023-22527 to execute arbitrary code in memory
CVE-2023-22527CRITICALsob ataqueransomware04 mar 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir ↗
Metasploit600
pgAdmin Session Deserialization RCE
CVE-2024-2044CRITICAL04 mar 2024
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
65RISCO
abrir ↗
Metasploit600
Judge0 sandbox escape
CVE-2024-28189CRITICAL04 mar 2024
Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
43RISCO
abrir ↗
← anteriorpágina 489 / 2.737próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.