Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL13 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
MandipJoshi/CVE-2021-3560
CVE-2021-3560HIGHbajo ataque13 may 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
CVE-2025-3248CRITICALbajo ataqueransomware13 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2025-4603CRITICAL12 may 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RIESGO
abrir
GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
CVE-2023-37582CRITICAL12 may 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC3
rebelle3/cve-2017-7117
CVE-2017-711712 may 2025
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir
GitHub PoC
shishirpandey18/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque12 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC55
WHW0x455/CVE-2023-41992
CVE-2023-41992HIGHbajo ataque12 may 2025
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RIESGO
abrir
GitHub PoC
使用PowsrShell掃描CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware12 may 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
PolarisXSec/CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque11 may 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
fatkz/CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque11 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
Windows & linux support
CVE-2023-42793CRITICALbajo ataqueransomware11 may 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass
CVE-2025-0411HIGHbajo ataque11 may 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
GitHub PoC
SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC
CVE-2025-31324CRITICALbajo ataqueransomware10 may 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC2
WordPress PDF 2 Post Plugin <= 2.4.0 is vulnerable to Remote Code Execution (RCE) +Subscriber
CVE-2025-32583CRITICAL10 may 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RIESGO
abrir
GitHub PoC
Remote Code Execution (RCE) vulnerability in Apache Tomcat.
CVE-2025-24813CRITICALbajo ataque10 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC3
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
CVE-2025-4403CRITICAL10 may 2025
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
48RIESGO
abrir
GitHub PoC
PoC for CVE-2017-5487 - WordPress User Enumeration via REST
CVE-2017-548710 may 2025
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC
congdong007/CVE-2025-29306_poc
CVE-2025-29306CRITICAL10 may 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC1
Apache CXF SSRF CVE-2024-28752
CVE-2024-28752CRITICAL10 may 2025
Apache CXF SSRF Vulnerability using the Aegis databinding
63RIESGO
abrir
GitHub PoC
This is an exercise built around CVE-2021-3560
CVE-2021-3560HIGHbajo ataque09 may 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC8
exploit for CVE-2025-27533, a Denial of Service (DoS) vulnerability in Apache ActiveMQ
CVE-2025-27533MEDIUM09 may 2025
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
33RIESGO
abrir
GitHub PoC
CVE-2024-38475 Scanner using FFUF + Seclists
CVE-2024-38475CRITICALbajo ataque09 may 2025
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir
GitHub PoC2
WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation
CVE-2025-3605CRITICAL09 may 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
GitHub PoC
Tools for scan CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
CVE-2024-25600CRITICAL09 may 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
The Web Is Vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware08 may 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
sap-netweaver-cve-2025-31324-check
CVE-2025-31324CRITICALbajo ataqueransomware08 may 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
x-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass
CVE-2025-29927CRITICAL08 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
exploiting CVE-2025-27007, a critical unauthenticated privilege escalation vulnerability in the OttoKit (formerly SureTriggers) WordPress plugin
CVE-2025-27007CRITICAL07 may 2025
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RIESGO
abrir
GitHub PoC1
1Altruist/CVE-2025-46271-Reverse-Shell-PoC
CVE-2025-46271CRITICAL07 may 2025
Planet Technology Network Products OS Command Injection
48RIESGO
abrir
anteriorpágina 158 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.