Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC
shun1403/PIL-CVE-2017-8291-study
CVE-2017-8291HIGHbajo ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
Dowonkwon/drupal-cve-2018-7600-poc
CVE-2018-7600CRITICALbajo ataqueransomware27 abr 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.
CVE-2025-24813CRITICALbajo ataque27 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RIESGO
abrir
GitHub PoC1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 abr 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALbajo ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHbajo ataqueransomware26 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC1
Erlang OTP SSH NSE Discovery Script
CVE-2025-32433CRITICALbajo ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A PoC of CVE-2019-5420 I made for PentesterLab
CVE-2019-542025 abr 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALbajo ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 abr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHbajo ataqueransomware25 abr 2025
Information disclosure
100RIESGO
abrir
GitHub PoC3
CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP
CVE-2025-32433CRITICALbajo ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALbajo ataqueransomware25 abr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
CVE-2016-209825 abr 2025
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC5
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
CVE-2025-29306CRITICAL25 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHbajo ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RIESGO
abrir
GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
CVE-2023-1545HIGH25 abr 2025
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-011425 abr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
CVE-2025-31161 python exploit
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC1
Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
unzip-stream file write/overwrite vulnerability
CVE-2024-42471HIGH24 abr 2025
Arbitrary File Write via artifact extraction in actions/artifact
41RIESGO
abrir
GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
CVE-2025-34028CRITICALbajo ataque24 abr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
GitHub PoC3
Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities
CVE-2025-30208MEDIUM24 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
CVE-2018-1574524 abr 2025
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
GitHub PoC12
Exploit for CVE-2025-30406
CVE-2025-30406CRITICALbajo ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
GitHub PoC
JIYUN02/cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware24 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
tar-fs file write/overwrite vulnerability
CVE-2024-12905HIGH24 abr 2025
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted
41RIESGO
abrir
anteriorpágina 153 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.