Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.505exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC4
numanturle/CVE-2025-25279
CVE-2025-25279CRITICAL24 feb 2025
Arbitrary file read in Mattermost Boards via import & export board archive
53RIESGO
abrir
GitHub PoC3
shishirghimir/CVE-2024-53677-Exploit
CVE-2024-53677CRITICAL24 feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
CVE-2013-3900MEDIUMbajo ataque23 feb 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
CVE-2024-10924CRITICAL23 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
CVE-2025-0411HIGHbajo ataque23 feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
GitHub PoC
Example usage: exploit.sh http://site.com
CVE-2023-1545HIGH22 feb 2025
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir
GitHub PoC1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALbajo ataque21 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC4
CVE-2023-1698 Proof of Concept (PoC)
CVE-2023-1698CRITICAL21 feb 2025
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
GitHub PoC1
funixone/CVE-2024-24919---Exploit-Script
CVE-2024-24919HIGHbajo ataqueransomware21 feb 2025
Information disclosure
100RIESGO
abrir
GitHub PoC5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALbajo ataque20 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC
CVE-2025-24971 exploit
CVE-2025-24971CRITICAL20 feb 2025
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RIESGO
abrir
GitHub PoC2
PoC of the vulnerability CVE-2024-23346
CVE-2024-23346CRITICAL20 feb 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
GitHub PoC
anu
CVE-2024-1651CRITICAL20 feb 2025
Torrentpier 2.4.1 - RCE
60RIESGO
abrir
GitHub PoC
POC for CVE-2023-44487
CVE-2023-44487HIGHbajo ataque19 feb 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC1
ishwardeepp/CVE-2025-0411-MoTW-PoC
CVE-2025-0411HIGHbajo ataque19 feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
GitHub PoC1
PAN-OS CVE POC SCRIPT
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
GitHub PoC2
NSE script that checks for CVE-2025-0108 vulnerability in Palo Alto Networks PAN-OS
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
GitHub PoC
barcrange/CVE-2025-0108-Authentication-Bypass-checker
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2024-34716CRITICAL19 feb 2025
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RIESGO
abrir
GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
CVE-2023-47268MEDIUM19 feb 2025
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RIESGO
abrir
GitHub PoC
Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523
CVE-2011-252319 feb 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
CVE-2008-465419 feb 2025
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
GitHub PoC
Exploitation Script for CVE-2021-3560
CVE-2021-3560HIGHbajo ataque18 feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC13
Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others
CVE-2024-13159CRITICALbajo ataque18 feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
GitHub PoC
CVE-2023-4911-Looney-Tunables
CVE-2023-4911HIGHbajo ataque18 feb 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC2
Detects an authentication bypass vulnerability in Palo Alto PAN-OS (CVE-2025-0108).
CVE-2025-0108HIGHbajo ataque18 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
GitHub PoC3
sariamubeen/CVE-2023-7028
CVE-2023-7028CRITICALbajo ataque17 feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
GitHub PoC
This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.
CVE-2021-44228CRITICALbajo ataqueransomware17 feb 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.
CVE-2024-4367MEDIUM17 feb 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC1
skrkcb2/CVE-2025-0851
CVE-2025-0851CRITICAL17 feb 2025
Path traversal issue in Deep Java Library
53RIESGO
abrir
anteriorpágina 177 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.