Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
13.307 exploits
GitHub PoC★ 1
Zenar CMS 9.3 suffers from an unrestricted file upload vulnerability in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RIESGO
abrir ↗GitHub PoC★ 32
POC of CVE-2025-7783
Usage of unsafe random function in form-data for choosing boundary
48RIESGO
abrir ↗GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 1
Joelp03/CVE-2025-49113
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗GitHub PoC★ 8
Exploit para explotar la vulnerabilidad CVE-2025-32463
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC★ 8
Exploit para explotar la vulnerabilidad CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 1
blindma1den/CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗GitHub PoC
admin-ping/CVE-2025-48384-RCE
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC
PoC of cve-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir ↗GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC
This is the exploit for the CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir ↗GitHub PoC
Floodnut/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC
malaya-m/cve-2013-3900-remediation-report
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC
Detection for CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗GitHub PoC
CVE-2025-53833
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RIESGO
abrir ↗GitHub PoC★ 2
joelczk/CVE-2025-52688
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RIESGO
abrir ↗GitHub PoC
Kalidas-7/CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC★ 1
krypton-0x00/CVE-2025-32463-Chwoot-POC
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RIESGO
abrir ↗GitHub PoC
ECHO6789/CVE-2025-48384-submodule
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗GitHub PoC★ 2
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗GitHub PoC
mheranco/CVE-2025-44136
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir ↗GitHub PoC★ 48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.