Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
hklabCR/CVE-2011-2523
CVE-2011-252306 jul 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC2
NoobCat2000/CVE-2022-37969
CVE-2022-37969HIGHbajo ataque06 jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC1
An analysis and demonstration of the unauthenticated SQL Injection vulnerability (CVE-2022-3141) in ACS EDU 3rd Gen.
CVE-2022-314106 jul 2025
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RIESGO
abrir
GitHub PoC2
CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by default
CVE-2024-55963MEDIUM06 jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RIESGO
abrir
GitHub PoC1
🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]
CVE-2025-29927CRITICAL06 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Citrix Bleed 2 PoC Scanner (CVE-2025-5777)
CVE-2025-5777CRITICALbajo ataqueransomware06 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC2
CitrixBleed-2 Checker & Poc automatic exploit and check token.
CVE-2025-5777CRITICALbajo ataqueransomware06 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware05 jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).
CVE-2025-5777CRITICALbajo ataqueransomware05 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
CitrixBleed2 poc
CVE-2025-5777CRITICALbajo ataqueransomware05 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Royall-Researchers/CVE-2024-9264
CVE-2024-9264CRITICAL05 jul 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque05 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC2
gmh5225/CVE-2025-6554-2
CVE-2025-6554HIGHbajo ataque05 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC3
ibrahmsql/CVE-2021-41163
CVE-2021-41163CRITICAL05 jul 2025
RCE via malicious SNS subscription payload
53RIESGO
abrir
GitHub PoC
Papercut Vulnerability, Affected Versions are PaperCut MF or NG version 8.0 or later (excluding patched versions) on all OS platforms.
CVE-2023-27350CRITICALbajo ataqueransomware05 jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC3
cve-2025-32462' demo
CVE-2025-32462LOW05 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC
Grafana RCE
CVE-2024-9264CRITICAL05 jul 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC
Royall-Researchers/CVE-2025-24071
CVE-2025-24071MEDIUM05 jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC2
ibrahmsql/discourse-CVE-2021-41163
CVE-2021-41163CRITICAL05 jul 2025
RCE via malicious SNS subscription payload
53RIESGO
abrir
GitHub PoC
gmh5225/CVE-2025-6554
CVE-2025-6554HIGHbajo ataque05 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC
Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure token generation, SSL bypass, and improved output.
CVE-2024-4040CRITICALbajo ataque04 jul 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC5
Unauthenticated Remote Code Execution exploit for CVE-2025-20281 in Cisco ISE ERS API. Execute commands or launch reverse shells as root — no authentication required.
CVE-2025-20281CRITICALbajo ataque04 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2023-46747-RCE PoC
CVE-2023-46747CRITICALbajo ataqueransomware04 jul 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
GitHub PoC
Privilege escalation exploit for CVE-2025-32463 using a malicious NSS module injected via sudo -R. This version creates a stealth payload called illdeed, granting root access through a controlled chroot environment.
CVE-2025-32463CRITICALbajo ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC2
POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.
CVE-2021-29447HIGH04 jul 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)
CVE-2025-47812CRITICALbajo ataque04 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC1
🛡️ Proof of Concept (PoC) for CVE-2025-32463 — Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
CVE-2025-32463CRITICALbajo ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC8
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
CVE-2025-32462LOW04 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC15
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
CVE-2025-32463CRITICALbajo ataque04 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”
CVE-2025-5777CRITICALbajo ataqueransomware04 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
anteriorpágina 138 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.