Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
13.627 exploits
GitHub PoC1
CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins, risking RCE, SQLi, XSS, and backdoors.
CVE-2024-11972CRITICAL13 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
GitHub PoC1
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
CVE-2024-10571CRITICAL13 ene 2025
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-10586-Poc
CVE-2024-10586CRITICAL12 ene 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RIESGO
abrir
GitHub PoC4
# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]
CVE-2025-0282CRITICALbajo ataqueransomware12 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)
CVE-2024-9707CRITICAL12 ene 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RIESGO
abrir
GitHub PoC2
kcfg bypass example - CVE-2024-21338
CVE-2024-21338HIGHbajo ataqueransomware12 ene 2025
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC1
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection
CVE-2024-50491CRITICAL12 ene 2025
WordPress RSVP ME plugin <= 1.9.9 - SQL Injection vulnerability
48RIESGO
abrir
GitHub PoC1
Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection
CVE-2023-32590CRITICAL12 ene 2025
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RIESGO
abrir
GitHub PoC1
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
CVE-2024-3605CRITICAL12 ene 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RIESGO
abrir
GitHub PoC17
CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
CVE-2024-50603CRITICALbajo ataque12 ene 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RIESGO
abrir
GitHub PoC1
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
CVE-2024-12877CRITICAL11 ene 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir
GitHub PoC
A Python script to detect CVE-2024-41713, a directory traversal vulnerability in Apache HTTP Server, enabling unauthorized access to restricted resources. This tool is for educational purposes and authorized testing only. Unauthorized usage is unethical and illegal.
CVE-2024-41713CRITICALbajo ataqueransomware11 ene 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC1
Bludit 3.9.2 - Auth Bruteforce Bypass CVE:2019-17240 Refurbish In bash
CVE-2019-17240LOW11 ene 2025
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC
poc-cve-2023-3824
CVE-2023-3824CRITICAL11 ene 2025
Buffer overflow and overread in phar_dir_read()
48RIESGO
abrir
GitHub PoC
Exploit implementation for CVE-2021-21551
CVE-2021-21551HIGHbajo ataque11 ene 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC53
CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overflow exploit.
CVE-2025-0282CRITICALbajo ataqueransomware11 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-9932-POC
CVE-2024-9932CRITICAL11 ene 2025
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
Nxploited/CVE-2024-49328-exploit
CVE-2024-49328CRITICAL11 ene 2025
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RIESGO
abrir
GitHub PoC
XSS Test Swagger 3.14.1 to 3.37.0
CVE-2025-8191MEDIUM10 ene 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir
GitHub PoC2
Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)
CVE-2024-36840CRITICAL10 ene 2025
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RIESGO
abrir
GitHub PoC3
Vulnerable Environment and Exploit for CVE-2024-53677
CVE-2024-53677CRITICAL10 ene 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC1
punitdarji/Apache-struts-cve-2024-53677
CVE-2024-53677CRITICAL08 ene 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
The **Dirty Pipe exploit (CVE-2022-0847)** is a Linux kernel vulnerability (v5.8+) allowing unprivileged attackers to overwrite arbitrary files via a flaw in the pipe mechanism. This leads to privilege escalation, granting root access. Similar to Dirty Cow but easier to exploit. Fix: Update to a patched kernel version.
CVE-2022-0847HIGHbajo ataque08 ene 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC12
CVE-2024-49112 LDAP RCE PoC and Metasploit Module
CVE-2024-49112CRITICAL08 ene 2025
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC5
Fuel CMS 1.4.1 - Remote Code Execution
CVE-2018-1676308 ene 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
Taldrid1/cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware07 ene 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC121
GeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具
CVE-2024-36401CRITICALbajo ataque07 ene 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC
JustinYe377/CTF-CVE-2022-0847
CVE-2022-0847HIGHbajo ataque07 ene 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC3
An rewritten POC on the CVE-2014-3704
CVE-2014-370406 ene 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
GitHub PoC6
CRUNZEX/CVE-2025-22968
CVE-2025-22968CRITICAL05 ene 2025
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho
48RIESGO
abrir
anteriorpágina 183 / 455siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.