Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.320 exploits
GitHub PoC
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
CVE-2024-40453CRITICAL08 jun 2025
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com
48RIESGO
abrir
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHbajo ataqueransomware08 jun 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
CVE-2025-31131
CVE-2025-31131HIGH07 jun 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
GitHub PoC
CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc
CVE-2024-51482CRITICAL07 jun 2025
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RIESGO
abrir
GitHub PoC
CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware07 jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC1
CVE-2017-5638 Exploit Rewritten In Python By haxerr9
CVE-2017-5638CRITICALbajo ataqueransomware07 jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
POC
CVE-2025-30208MEDIUM06 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC90
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALbajo ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALbajo ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in the Pluggable Authentication Module (PAM) `pam_unix_auth` when handling keyboard-interactive authentication in SSH.
CVE-2020-14871CRITICALbajo ataque06 jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
GitHub PoC18
mbanyamer/CVE-2025-24076
CVE-2025-24076HIGH06 jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALbajo ataqueransomware06 jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHbajo ataque05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC3
rasool13x/exploit-CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RIESGO
abrir
GitHub PoC198
Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
CVE-2025-32756CRITICALbajo ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-1284004 jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHbajo ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
A repository used for Hackthebox ServMon Machine
CVE-2019-20085HIGHbajo ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC104
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC3
CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALbajo ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC33
CVE-2025-4123 - Grafana Tool
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
GitHub PoC
MantisToboggan-git/CVE-2025-4632-POC
CVE-2025-4632CRITICALbajo ataque04 jun 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RIESGO
abrir
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 jun 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC2
r007sec/CVE-2024-53677
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-468803 jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir
GitHub PoC
imbas007/CVE-2025-4123-template
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
GitHub PoC5
Detection for CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque03 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
anteriorpágina 145 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.