Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC2
CrushFTP CVE-2025-31161 Exploit Tool 🔓
CVE-2025-31161CRITICALbajo ataqueransomware21 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC1
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALbajo ataque21 abr 2025
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC2
A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects Wazuh versions ≥ 4.4.0 and has been patched in version 4.9.1.
CVE-2025-24016CRITICALbajo ataque21 abr 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2023-43770MEDIUMbajo ataque20 abr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RIESGO
abrir
GitHub PoC2
mouseos/cve-2019-2215_SH-M08
CVE-2019-2215HIGHbajo ataque20 abr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2021-44026CRITICALbajo ataque20 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2020-0796CRITICALbajo ataqueransomware20 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2019-7238CRITICALbajo ataque20 abr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2020-35730MEDIUMbajo ataque20 abr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RIESGO
abrir
GitHub PoC
JenmrR/Node.js-CVE-2024-39943
CVE-2024-39943CRITICAL19 abr 2025
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RIESGO
abrir
GitHub PoC1
cybermads/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
pruthuraut/CVE-2025-28121
CVE-2025-28121MEDIUM19 abr 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p
33RIESGO
abrir
GitHub PoC
Go-based exploit for CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC7
CVE-2023-38408 SSH Vulnerability Scanner & PoC
CVE-2023-38408CRITICAL19 abr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC6
0xPThree/cve-2025-32433
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC2
Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.
CVE-2022-0847HIGHbajo ataque19 abr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.
CVE-2024-8425CRITICAL19 abr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
GitHub PoC1
This is for educational porpuses only. Please do not use agains unathorized systems.
CVE-2024-42327CRITICAL18 abr 2025
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
Grand-Moomin/Vuln-Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL18 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
Exploitation module for CVE-2025-32433 (Erlang/OTP)
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC5
CVE-2025-24813的vulhub环境的POC脚本
CVE-2025-24813CRITICALbajo ataque18 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)
CVE-2024-4577CRITICALbajo ataqueransomware18 abr 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC5
python script to find vulnerable targets of CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
Erlang/OTP SSH 远程代码执行漏洞
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC3
Missing Authentication for Critical Function (CWE-306)-Exploit
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC4
PoC - CVE-2025-24071 / CVE-2025-24054, NTMLv2 hash'leri alınabilen bir vulnerability
CVE-2025-24054MEDIUMbajo ataque18 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC3
Security research on Erlang/OTP SSH CVE-2025-32433.
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Epivalent/CVE-2025-32433-detection
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC5
ekomsSavior/POC_CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC142
CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
anteriorpágina 163 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.