Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL07 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Heimd411/CVE-2025-24813-noPoC
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
VVeakee/CVE-2024-4367
CVE-2024-4367MEDIUM06 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
Koray123-debug/CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque06 abr 2025
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
CVE-2025-2005CRITICAL06 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
CVE-2024-10924CRITICAL06 abr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC2
CVE-2025-24813-POC JSP Web Shell Uploader
CVE-2025-24813CRITICALbajo ataque06 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALbajo ataque06 abr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
cybermads/CVE-2011-2523
CVE-2011-252306 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC32
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHbajo ataque06 abr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC4
simple exp for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
CVE-2025-30065 PoC
CVE-2025-30065CRITICAL05 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC1
Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.
CVE-2025-24813CRITICALbajo ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
Vite-CVE-2025-30208-EXP单目标检测,支持自定义读取路径,深度检索
CVE-2025-30208MEDIUM05 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
CVE-2011-252305 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header
CVE-2025-29927CRITICAL05 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
CVE-2025-31131HIGH04 abr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
GitHub PoC
all3njk/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
PoC for CVE-2024-25600
CVE-2024-25600CRITICAL04 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)
CVE-2024-23897CRITICALbajo ataqueransomware04 abr 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC7
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantiate arbitrary record types during parsing, enabling code execution when untrusted data is processed without proper controls.
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC12
PoC
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
sn1p3rt3s7/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)
CVE-2025-30911CRITICAL04 abr 2025
WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability
CVE-2021-38163CRITICALbajo ataque04 abr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir
GitHub PoC
Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) POC
CVE-2018-1942204 abr 2025
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
GitHub PoC1
h4ckxel/CVE-2025-2005
CVE-2025-2005CRITICAL03 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
CVE-2024-53900CRITICAL03 abr 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir
anteriorpágina 167 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.