Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
Agampreet-Singh/CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware07 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
PoC to inject a command via the DEVICE_PING endpoint
CVE-2025-7769HIGH07 ago 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RIESGO
abrir
GitHub PoC4
soltanali0/CVE-2025-5777-Exploit
CVE-2025-5777CRITICALbajo ataqueransomware07 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC1
🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August 2025 through Forage. It focuses on detecting, analyzing, and mitigating a simulated real-world cyberattack involving the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALbajo ataque06 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
PoC for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque06 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC1
Simulated PoC for CVE-2025-54253: Adobe AEM OGNL Injection Vulnerability
CVE-2025-54253CRITICALbajo ataque06 ago 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RIESGO
abrir
GitHub PoC1
Automated scanner + exploit for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque06 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-
CVE-2020-0796CRITICALbajo ataqueransomware06 ago 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
CVE-2025-54574
CVE-2025-54574CRITICAL05 ago 2025
Squid's URN Handling can lead to Buffer Overflow
53RIESGO
abrir
GitHub PoC
Penetration test targeting CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque05 ago 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC
Webmin CVE-2022-0824 增强版漏洞利用工具 - 支持命令执行和反向Shell双模式
CVE-2022-0824HIGH05 ago 2025
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
GitHub PoC
Proof-of-Concept exploit for CVE-2025-24893, an unauthenticated Remote Code Execution (RCE) vulnerability in XWiki. Exploits a template injection flaw in the SolrSearch endpoint via Groovy script execution.
CVE-2025-24893CRITICALbajo ataque05 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
PoC | XWiki Platform 15.10.10 - Remote Code Execution
CVE-2025-24893CRITICALbajo ataque05 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
painoob/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque05 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
Questo script è un proof of concept (PoC) che dimostra una tecnica di privilege escalation (Elevazione di privilegi) sfruttando una vulnerabilità teorica di sudo (es. CVE-2025-32463). Il PoC forza sudo a caricare una libreria .so manipolata sfruttando la funzionalità -R (chroot) e la configurazione personalizzata di NSS (nsswitch.conf).
CVE-2025-32463CRITICALbajo ataque05 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC2
binneko/CVE-2025-50286
CVE-2025-50286HIGH05 ago 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir
GitHub PoC
CVE-2013-3900 WinVerifyTrust Signature
CVE-2013-3900MEDIUMbajo ataque04 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
A simple Log4j PoC written in Go
CVE-2021-44228CRITICALbajo ataqueransomware04 ago 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose
CVE-2018-7600CRITICALbajo ataqueransomware04 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC17
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro.
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC22
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
CVE-2020-0688HIGHbajo ataqueransomware04 ago 2025
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
Kai-One001/WordPress-HT-Contact-CVE-2025-7340-RCE
CVE-2025-7340CRITICAL04 ago 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC1
beishanxueyuan/CVE-2025-48384-test
CVE-2025-48384HIGHbajo ataque04 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
fluoworite/CVE-2025-48384-sub
CVE-2025-48384HIGHbajo ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
PoC for CVE-2025-48384
CVE-2025-48384HIGHbajo ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
beishanxueyuan/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque03 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task was to showcase how attackers can weaponize compressed archive files to gain remote access to a target machine.
CVE-2023-38831HIGHbajo ataqueransomware03 ago 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.
CVE-2012-298203 ago 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC5
Tribell Edge Sandbox Escape - PoCs of Edge's legacy vulnerabilities BadgeUpdateManager / TileFlyoutUpdateManager / ToastNotificationManager to exploit cross-boundary XmlDocument sharing and escape Edge’s LPAC sandbox (CVE-2019-0555).
CVE-2019-055503 ago 2025
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RIESGO
abrir
anteriorpágina 128 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.