Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir
GitHub PoC
Technical Details and Exploit for CVE-2025-50460
CVE-2025-50460CRITICAL30 jul 2025
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i
48RIESGO
abrir
GitHub PoC4
本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。
CVE-2025-32463CRITICALbajo ataque30 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29824HIGHbajo ataqueransomware30 jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC1
Technical Details and Exploit for CVE-2025-50472
CVE-2025-50472CRITICAL30 jul 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste
48RIESGO
abrir
GitHub PoC1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
CVE-2025-14847HIGHbajo ataque30 jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
rgvillanueva28/vulnbox-easy-CVE-2025-29927
CVE-2025-29927CRITICAL30 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALbajo ataqueransomware30 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)
CVE-2020-1022030 jul 2025
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir
GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
CVE-2017-5638CRITICALbajo ataqueransomware30 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
CVE-2025-32463CRITICALbajo ataque29 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
CVE-2025-53770CRITICALbajo ataqueransomware29 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
DLL00P/CVE-2021-1675
CVE-2021-1675HIGHbajo ataqueransomware29 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Ai相关
CVE-2025-54381CRITICAL29 jul 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir
GitHub PoC
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
CVE-2021-43857CRITICAL29 jul 2025
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir
GitHub PoC
→ poc for CVE-2025-29927
CVE-2025-29927CRITICAL29 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC5
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
CVE-2025-24813CRITICALbajo ataque28 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
imbas007/CVE-2025-32429-Checker
CVE-2025-32429CRITICAL28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability
CVE-2023-34362CRITICALbajo ataqueransomware28 jul 2025
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
CVE-2025-8191MEDIUM28 jul 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir
GitHub PoC2
Exploit for CVE-2022-35411 — Unauthenticated RCE in rpc.py (<= 0.6.0)
CVE-2022-3541128 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir
GitHub PoC1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462LOW28 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC
Tools for detecting and assessing systems vulnerable to CVE-2025-53770 (CWE-502: Deserialization of Untrusted Data).
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC15
CVE-2025-53770 Mass Scanner
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
An activity to train analysis skills and reporting
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
The POC for m6.fr website
CVE-2025-29927CRITICAL27 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
anteriorpágina 130 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.