Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
13.264 exploits
GitHub PoC798
CVE-2025-55182 POC
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
sudlit/CVE-2017-7494
CVE-2017-7494CRITICALbajo ataqueransomware02 dic 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC1
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
CVE-2025-29927CRITICAL02 dic 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
Jorge2Rubio/CVE-2019-0232
CVE-2019-023202 dic 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
boro03/CVE-2021-4034
CVE-2021-4034HIGHbajo ataque02 dic 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Vulnerable environment for testing CVE-2021-22941 Nuclei template
CVE-2021-22941CRITICALbajo ataqueransomware02 dic 2025
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RIESGO
abrir
GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
CVE-2021-21551HIGHbajo ataque02 dic 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC
towaos/towaos-lab-cve-2020-11023
CVE-2020-11023MEDIUMbajo ataque02 dic 2025
Potential XSS vulnerability in jQuery
85RIESGO
abrir
GitHub PoC2
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)
CVE-2025-64459CRITICAL01 dic 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC
letsr00t/CVE-2013-2094
CVE-2013-2094HIGHbajo ataque01 dic 2025
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
GitHub PoC8
Reverse engineering research and custom firmware for the Allwinner V3-based SJCAM SJ4000 Air, including firmware parsers, an AVIOCTRL client, security research, and the CVE-2026-52656 proof of concept.
CVE-2026-52656CRITICAL01 dic 2025
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a
48RIESGO
abrir
GitHub PoC11
Outlook exploitation
CVE-2024-21413CRITICALbajo ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
sec-dojo-com/CVE-2020-24186
CVE-2020-24186CRITICAL29 nov 2025
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
CVE-2025-8088HIGHbajo ataque29 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
KylVGoi/cve-2019-1663
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
GitHub PoC1
m2hcz/CVE-2025-6440-Poc-Exploit
CVE-2025-6440CRITICAL29 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
CVE-2018-10933 - LibSSH - Authentication Bypass
CVE-2018-10933CRITICAL29 nov 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
Exploit - CVE-2023-26360
CVE-2023-26360HIGHbajo ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
GitHub PoC
AndrewMas99/CVE-2019-11043-Vulnerability
CVE-2019-11043HIGHbajo ataqueransomware28 nov 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
CVE-2010-2075
CVE-2010-207528 nov 2025
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC
Modified the CVE-2024-25600
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2021-43798 is a high-severity path traversal vulnerability (CVSS 3.1 score: 7.5) affecting Grafana versions 8.0.0-beta1 through 8.3.0. It allows unauthenticated attackers to read arbitrary files from the server by exploiting improper sanitization in the /public/plugins/:pluginId endpoint
CVE-2021-43798HIGHbajo ataque27 nov 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC
CVE-2025-58360
CVE-2025-58360HIGHbajo ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC6
XXE through a specific endpoint /geoserver/wms operation GetMap - Geoserver
CVE-2025-58360HIGHbajo ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.
CVE-2025-55315CRITICAL27 nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RIESGO
abrir
GitHub PoC
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CVE-2025-32433CRITICALbajo ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Chroot Privilege Escalation
CVE-2025-32463CRITICALbajo ataque27 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.
CVE-2023-42793CRITICALbajo ataqueransomware27 nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC4
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
CVE-2025-12735CRITICAL27 nov 2025
CVE-2025-12735
48RIESGO
abrir
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHbajo ataqueransomware27 nov 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
anteriorpágina 105 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.