Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC
Next.js CVE-2025-29927 Hunter
CVE-2025-29927CRITICAL11 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
Unverified Password Change (CWE-620)
CVE-2024-48887CRITICAL10 abr 2025
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c
53RIESGO
abrir
GitHub PoC4
TomcatScanner is a comprehensive security tool designed for detecting and exploiting the CVE-2025-24813 vulnerability in Apache Tomcat servers.
CVE-2025-24813CRITICALbajo ataque10 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC3
CVE-2019-15107-Scanner is a Python-based scanner that detects vulnerable Webmin (1.890 - 1.920) servers affected by CVE-2019-15107, an unauthenticated remote code execution (RCE) vulnerability in the /password_change.cgi endpoint.
CVE-2019-15107CRITICALbajo ataqueransomware10 abr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC9
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
CVE-2025-3248CRITICALbajo ataqueransomware10 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC1
Exploit CVE-2025-1974 with a single file.
CVE-2025-1974CRITICAL10 abr 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Exploit CVE-2025-69985 to bypass authentication and execute remote commands on FUXA versions ≤ 1.2.8 via the /api/runscript endpoint.
CVE-2025-69985CRITICAL10 abr 2025
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RIESGO
abrir
GitHub PoC9
CVE-2025-24813 poc
CVE-2025-24813CRITICALbajo ataque10 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC2
POC of CVE-2025-3248, RCE of LangFlow
CVE-2025-3248CRITICALbajo ataqueransomware10 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC18
CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE
CVE-2025-22457CRITICALbajo ataqueransomware10 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC73
PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways
CVE-2025-22457CRITICALbajo ataqueransomware09 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.
CVE-2025-29927CRITICAL09 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
a lightweight JavaScript snippet showcasing how unauthorized password changes can be triggered on vulnerable Fortinet FortiSwitch GUI endpoints.
CVE-2024-48887CRITICAL09 abr 2025
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c
53RIESGO
abrir
GitHub PoC
OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.
CVE-2024-25600CRITICAL09 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC1
A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).
CVE-2025-24813CRITICALbajo ataque09 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
sandsoncosta/CVE-2025-26633
CVE-2025-26633HIGHbajo ataqueransomware08 abr 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RIESGO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque08 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC48
Proof of Concept for CVE-2025-31161 / CVE-2025-2825
CVE-2025-31161CRITICALbajo ataqueransomware08 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
pickovven/vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
0xnxt1me/CVE-2025-29927
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
CVE-2025-31651 PoC
CVE-2025-31651CRITICAL08 abr 2025
Apache Tomcat: Bypass of rules in Rewrite Valve
48RIESGO
abrir
GitHub PoC2
Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN
CVE-2025-22457CRITICALbajo ataqueransomware08 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
Project Repository for Exploitation, Detection and Mitigation of Folina Vulnerability (CVE-2022-30190)
CVE-2022-30190HIGHbajo ataqueransomware08 abr 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
CVE-2019-5418HIGHbajo ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC3
mouadk/parquet-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL07 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
CVE-2023-23397CRITICALbajo ataque07 abr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Heimd411/CVE-2025-24813-noPoC
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
vances25/CVE-2024-44871
CVE-2024-44871HIGH07 abr 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RIESGO
abrir
anteriorpágina 166 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.