Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
CVE-2025-24813CRITICALbajo ataque30 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
CVE-2025-1097HIGH30 mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RIESGO
abrir
GitHub PoC1
Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927
CVE-2025-29927CRITICAL30 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Next.js Auth Bypass Lab ‐ CVE-2025-29927
CVE-2025-29927CRITICAL30 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
CVE-2009-1151CRITICALbajo ataque30 mar 2025
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
GitHub PoC1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
CVE-2020-11651CRITICALbajo ataque30 mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC
cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}
CVE-2022-26134CRITICALbajo ataqueransomware30 mar 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
Sets up a local Tapo C200 using CVE-2021-4045
CVE-2021-4045CRITICAL30 mar 2025
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
GitHub PoC
dustblessnotdust/CVE-2024-25180
CVE-2024-25180CRITICAL29 mar 2025
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf
48RIESGO
abrir
GitHub PoC1
Here is a simple but effective exploit for CVE-2025-29927.
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Next.js CVE-2025-29927 demonstration
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Sornphut/CVE-2023-7028-GitLab
CVE-2023-7028CRITICALbajo ataque29 mar 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
CVE-2025-24071MEDIUM29 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque28 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALbajo ataqueransomware28 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALbajo ataque28 mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir
GitHub PoC92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
liemkaka/CVE-2018-9206
CVE-2018-920627 mar 2025
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC7
CVE-2025-29927에 대한 설명 및 리서치
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
anteriorpágina 169 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.