Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.625 exploits
GitHub PoC4
PoC - CVE-2025-24071 / CVE-2025-24054, NTMLv2 hash'leri alınabilen bir vulnerability
CVE-2025-24054MEDIUMbajo ataque18 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC5
python script to find vulnerable targets of CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC16
The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC142
CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
FortiGate SSL-VPN CVE-2023-27997 Exploit PoC Script with ROP Chain
CVE-2023-27997CRITICALbajo ataqueransomware18 abr 2025
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir
GitHub PoC5
ekomsSavior/POC_CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)
CVE-2024-4577CRITICALbajo ataqueransomware18 abr 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
This is for educational porpuses only. Please do not use agains unathorized systems.
CVE-2024-42327CRITICAL18 abr 2025
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC5
CVE-2025-24813的vulhub环境的POC脚本
CVE-2025-24813CRITICALbajo ataque18 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
ethicalPap/CVE-2025-29775
CVE-2025-29775CRITICAL17 abr 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
48RIESGO
abrir
GitHub PoC2
verylazytech/CVE-2025-29306
CVE-2025-29306CRITICAL17 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC
NGINX Security Hardening & Vulnerability Remediation Analysis of critical CVEs (CVE-2021-23017, HTTP/2 DoS flaws) in outdated NGINX versions, with actionable steps for mitigation: upgrades, HTTP/2 hardening, and patch automation. Includes Nessus scan validation and proactive monitoring strategies.
CVE-2021-2301717 abr 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC4
exploit script for CVE-2024-45436
CVE-2024-45436CRITICAL17 abr 2025
extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct
48RIESGO
abrir
GitHub PoC1
mhamzakhattak/CVE-2025-29927
CVE-2025-29927CRITICAL16 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC10
verylazytech/CVE-2025-3248
CVE-2025-3248CRITICALbajo ataqueransomware16 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
CVE-2024-3094 실습 환경 구축 및 보고
CVE-2024-3094CRITICAL16 abr 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal x-middleware-subrequest HTTP header. Demonstrates unauthorized access to protected routes and provides mitigation strategies.
CVE-2025-29927CRITICAL16 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
enochgitgamefied/NextJS-CVE-2025-29927
CVE-2025-29927CRITICAL16 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.
CVE-2018-14847CRITICALbajo ataque16 abr 2025
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC
CMS Made Simple ≤ 2.2.9 SQL Injection Vulnerability CVE-2019-9053 is a vulnerability found in CMS Made Simple (CMSMS) versions up to 2.2.9, where the application is vulnerable to a blind time-based SQL injection
CVE-2019-905315 abr 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
CVE-2019-9053.
CVE-2019-905315 abr 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
celsius026/poc_CVE-2025-24016
CVE-2025-24016CRITICALbajo ataque15 abr 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL15 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
Exploits Python cve-2019-9053– by HackHeart
CVE-2019-905315 abr 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-41773HIGHbajo ataqueransomware14 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
AsierEgana/cve-2021-4034
CVE-2021-4034HIGHbajo ataque14 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
jakehomb/cve-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware14 abr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
pulentoski/Explotacion-CVE-2023-32315-Openfire
CVE-2023-32315HIGHbajo ataque14 abr 2025
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 abr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
GitHub PoC
CVE-2024-4367
CVE-2024-4367MEDIUM14 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
anteriorpágina 164 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.