Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
CVE-2025-49029CRITICAL01 jul 2025
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RIESGO
abrir
GitHub PoC1
depers-rus/CVE-2007-4559
CVE-2007-4559CRITICAL01 jul 2025
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
CVE-2025-32462LOW01 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC1
Proof of concept of CVE-2025-20282, the perfect 10.
CVE-2025-20282CRITICAL01 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
53RIESGO
abrir
GitHub PoC9
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL01 jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
4f-kira/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC29
CVE-2025-32463 Proof of concept
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC8
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderCMS. This tool uses PentestMonkey's PHP reverse shell script as the payload
CVE-2023-41425MEDIUM01 jul 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC54
Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC527
Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
CVE-2022-0847HIGHbajo ataque01 jul 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC31
Proof of Concept for CVE-2025-6218, demonstrating the exploitation of a vulnerability in WinRAR versions 7.11 and under, involving improper handling of archive extraction paths.
CVE-2025-6218HIGHbajo ataque01 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC2
7r00t/cve-2025-32463-lab
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC13
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC10
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC2
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.
CVE-2024-40898CRITICAL30 jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RIESGO
abrir
GitHub PoC
Citrix Bleed 2 PoC
CVE-2025-6543CRITICALbajo ataque30 jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RIESGO
abrir
GitHub PoC17
详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件
CVE-2025-5777CRITICALbajo ataqueransomware30 jun 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Simulação educacional de exploração de falha em dispositivos IoT com base no CVE-2017-17761
CVE-2017-1776130 jun 2025
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 130
23RIESGO
abrir
GitHub PoC
Exploit Code for CVE-2024-39930 gogs ssh server RCE
CVE-2024-39930CRITICAL29 jun 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RIESGO
abrir
GitHub PoC13
A simple proof of concept for WinRAR Path Traversal | RCE | CVE-2025-6218
CVE-2025-6218HIGHbajo ataque29 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC1
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
CVE-2025-30208MEDIUM29 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC2
Just poc for CVE 2024-54085
CVE-2024-54085CRITICALbajo ataque29 jun 2025
Redfish Authentication Bypass
90RIESGO
abrir
GitHub PoC1
obscura-cert/CVE-2025-33073
CVE-2025-33073HIGHbajo ataque28 jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC
aninfosec/CVE-2024-43425-Poc
CVE-2024-43425HIGH28 jun 2025
Moodle: remote code execution via calculated question types
78RIESGO
abrir
GitHub PoC
obscura-cert/CVE-2025-31650
CVE-2025-31650HIGH28 jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir
GitHub PoC1
POC for PDF JS' CVE-2024-4367 vuln
CVE-2024-4367MEDIUM28 jun 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC17
speinador/CVE-2025-6218_WinRAR
CVE-2025-6218HIGHbajo ataque27 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC21
Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
CVE-2025-20281CRITICALbajo ataque27 jun 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Security analysis project: Real-world CVE breakdown
CVE-2024-3094CRITICAL27 jun 2025
Xz: malicious code in distributed source
70RIESGO
abrir
anteriorpágina 140 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.