Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir
GitHub PoC
CVE-2025-41115
CVE-2025-41115CRITICAL24 nov 2025
Incorrect privilege assignment
53RIESGO
abrir
GitHub PoC
IS8123/CVE-2025-54381
CVE-2025-54381CRITICAL24 nov 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir
GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
CVE-2012-212224 nov 2025
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
GitHub PoC
CVE-2025-12762
CVE-2025-12762CRITICAL24 nov 2025
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RIESGO
abrir
GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
CVE-2023-36845CRITICALbajo ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
rashedhasan090/CVE-2025-5777
CVE-2025-5777CRITICALbajo ataqueransomware23 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
CVE-2025-10230CRITICAL23 nov 2025
Samba: command injection in wins server hook script
60RIESGO
abrir
GitHub PoC1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
CVE-2017-0199HIGHbajo ataqueransomware23 nov 2025
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC
CVE-2025-11833 Checker
CVE-2025-11833CRITICAL23 nov 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RIESGO
abrir
GitHub PoC2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
CVE-2025-24054MEDIUMbajo ataque23 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
Custom Docker Image
CVE-2017-7494CRITICALbajo ataqueransomware22 nov 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
POC
CVE-2025-5777CRITICALbajo ataqueransomware22 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC4
CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.
CVE-2025-26633HIGHbajo ataqueransomware22 nov 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RIESGO
abrir
GitHub PoC
ranasen-rat/CVE-2025-11001
CVE-2025-11001HIGH22 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
GitHub PoC7
CVE-2025-11001 (CVSS 7.0) – 7-Zip < 25.00 Directory Traversal → RCE via crafted ZIP with symlink. Allows arbitrary file write when extracted as Administrator. Fixed in 7-Zip 25.00 (July 2025).
CVE-2025-11001HIGH22 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
GitHub PoC1
Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)
CVE-2025-64446CRITICALbajo ataque21 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC2
A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.
CVE-2025-64459CRITICAL21 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC1
Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated SSRF or local file access.
CVE-2024-58258HIGH21 nov 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir
GitHub PoC1
SAP RCE auto-chain (CVE-2024-22127 + DIAG)
CVE-2024-22127CRITICAL21 nov 2025
Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
48RIESGO
abrir
GitHub PoC1
Adel-kaka-dz/cve-2025-59287
CVE-2025-59287CRITICALbajo ataque21 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
CVE-2025-61757CRITICALbajo ataque21 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir
GitHub PoC
Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.
CVE-2023-22515CRITICALbajo ataqueransomware21 nov 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC1
Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template processing in the "customCss()" method.
CVE-2025-47916CRITICAL21 nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
GitHub PoC1
Fully automated Confluence RCE exploit (CVE-2023-22527 + OGNL injection) 100% from scratch • Python • 2025
CVE-2023-22527CRITICALbajo ataqueransomware21 nov 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735CRITICAL21 nov 2025
CVE-2025-12735
48RIESGO
abrir
GitHub PoC1
Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table, three hunts (KQL/SPL/Sigma), first-4-hours comms, sample data, and figures. Built for fast triage; no org data; SharePoint Online out of scope.
CVE-2025-53770CRITICALbajo ataqueransomware21 nov 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Sorumluluk Reddi Kendi sorumluluğunuzda kullanın, size ait olmayan veya tarama izninizin olmadığı altyapılarda gerçekleştireceğiniz yasa dışı faaliyetlerden sorumlu olmayacağım.
CVE-2025-61882CRITICALbajo ataqueransomware21 nov 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir
GitHub PoC1
Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework
CVE-2022-22965CRITICALbajo ataque20 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.
CVE-2025-3248CRITICALbajo ataqueransomware20 nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
anteriorpágina 107 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.