Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC1
🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.
CVE-2025-31324CRITICALbajo ataqueransomware30 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
isabelacostaz/CVE-2019-0708-POC
CVE-2019-0708CRITICALbajo ataqueransomware30 abr 2025
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
TPLink VN020-F3v Denial of Service (CVE-2024-12342)
CVE-2024-12342HIGH29 abr 2025
TP-Link VN020 F3v(T) Incomplete SOAP Request WANIPConnection denial of service
41RIESGO
abrir
GitHub PoC
dev0558/CVE-2023-32243-Detection-and-Mitigation-in-WordPress
CVE-2023-32243CRITICAL29 abr 2025
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
GitHub PoC5
This is a CVE-2025-29927 Scanner.
CVE-2025-29927CRITICAL29 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers
CVE-2025-32433CRITICALbajo ataque29 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
rubbxalc/CVE-2025-29927
CVE-2025-29927CRITICAL29 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHbajo ataqueransomware29 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC
Detection, analysis, and response strategies for CVE-2024-3400 exploitation attempts targeting Palo Alto PAN-OS GlobalProtect portals. Includes IOCs, exploit patterns, and mitigation guidance.
CVE-2024-3400CRITICALbajo ataqueransomware29 abr 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers
CVE-2025-32433CRITICALbajo ataque29 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
CVE-2025-31324CRITICALbajo ataqueransomware29 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC6
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
CVE-2025-31324CRITICALbajo ataqueransomware28 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
Next js middlewareauth Bypass
CVE-2025-29927CRITICAL28 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
SPIP CVE-2023-27372 Unauthenticated RCE Exploit (Web Shell Upload)
CVE-2023-27372CRITICAL28 abr 2025
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC
SAP PoC para CVE-2025-31324
CVE-2025-31324CRITICALbajo ataqueransomware28 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC1
Nuclei template for cve-2025-31324 (SAP)
CVE-2025-31324CRITICALbajo ataqueransomware28 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
SAP NetWeaver Unauthenticated Remote Code Execution
CVE-2025-31324CRITICALbajo ataqueransomware28 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC1
CVE-2025-32433 is a vuln of ssh
CVE-2025-32433CRITICALbajo ataque28 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC4
Exploit para Poultry Farm Management System v1.0
CVE-2024-40110CRITICAL28 abr 2025
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2025-32433 Summary and Attack Overview
CVE-2025-32433CRITICALbajo ataque27 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC12
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
CVE-2025-31324CRITICALbajo ataqueransomware27 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC24
CVE-2025-31324, SAP Exploit
CVE-2025-31324CRITICALbajo ataqueransomware27 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
Updated exploit script for the CVE-2021-43798
CVE-2021-43798HIGHbajo ataque27 abr 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC25
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
CVE-2025-32432CRITICALbajo ataque27 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC1
yeahhbean/Laravel-CVE-2018-15133
CVE-2018-15133HIGHbajo ataque27 abr 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).
CVE-2024-27956CRITICAL27 abr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
shun1403/PIL-CVE-2017-8291-study
CVE-2017-8291HIGHbajo ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
airtiels 5650 CVE-2015-2797 PoC
CVE-2015-279727 abr 2025
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir
GitHub PoC
Dowonkwon/drupal-cve-2018-7600-poc
CVE-2018-7600CRITICALbajo ataqueransomware27 abr 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
CVE-2025-1974CRITICAL27 abr 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
anteriorpágina 152 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.