Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
The POC for m6.fr website
CVE-2025-29927CRITICAL27 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
QHxDr-dz/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC3
This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to insufficient handling of crafted SMB requests. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
CVE-2024-27686HIGH26 jul 2025
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic
41RIESGO
abrir
GitHub PoC
jkobierczynski/cve-2022-44268
CVE-2022-44268MEDIUM26 jul 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
Checks projects for compromised packages, suspicious files, and import statements.
CVE-2025-54313HIGHbajo ataque26 jul 2025
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RIESGO
abrir
GitHub PoC
Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows
CVE-2025-54313HIGHbajo ataque26 jul 2025
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RIESGO
abrir
GitHub PoC
Report written on CVE-2024-38112
CVE-2024-38112HIGHbajo ataque25 jul 2025
Windows MSHTML Platform Spoofing Vulnerability
93RIESGO
abrir
GitHub PoC
elprogramadorgt/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque25 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
This is my implementation of shellshock exploit
CVE-2014-6271CRITICALbajo ataque25 jul 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
G01d3nW01f/cve-2023-27372
CVE-2023-27372CRITICAL25 jul 2025
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC1
Udyz/CVE-2025-53770-Exploit
CVE-2025-53770CRITICALbajo ataqueransomware25 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Honeypot for CVE-2025-53770 aka ToolShell
CVE-2025-53770CRITICALbajo ataqueransomware25 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Just a quick script I cooked up to exploit CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware25 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC10
Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).
CVE-2025-32429CRITICAL25 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC
bharath-cyber-root/sharepoint-toolshell-cve-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware24 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Do you really think SharePoint is safe?
CVE-2025-53770CRITICALbajo ataqueransomware24 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHbajo ataqueransomware24 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Fineken/Jenkins-CVE-2024-23897-Lab
CVE-2024-23897CRITICALbajo ataqueransomware24 jul 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
CVE-2025-1302CRITICAL24 jul 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir
GitHub PoC7
DevBuiHieu/CVE-2025-6558-Proof-Of-Concept
CVE-2025-6558HIGHbajo ataque24 jul 2025
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RIESGO
abrir
GitHub PoC
rob0tstxt/POC-CVE-2025-5777
CVE-2025-5777CRITICALbajo ataqueransomware24 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Detection rules for CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware24 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC4
This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file to the hosted `CIF Analyzer` website on the target running on the Chemistry machine from Hack the Box.
CVE-2024-23346CRITICAL24 jul 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
GitHub PoC5
CVE-2024-4577 Mass Scanner & Exploit Tool
CVE-2024-4577CRITICALbajo ataqueransomware23 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2022-4288923 jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
Skac44/CVE-2024-38063
CVE-2024-38063CRITICAL23 jul 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
CVE-2025-53770CRITICALbajo ataqueransomware23 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
CVE-2017-12637HIGHbajo ataque23 jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RIESGO
abrir
GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
CVE-2025-53770CRITICALbajo ataqueransomware23 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 131 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.