Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
13.264 exploits
GitHub PoC★ 68
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RIESGO
abrir ↗GitHub PoC★ 7
# CVE-2025-64446 PoC - FortiWeb Path Traversal Proof of Concept para la vulnerabilidad de path traversal en Fortinet FortiWeb que permite ejecución remota de comandos. Incluye herramienta de detección para fines educativos. **⚠️ SOLO USO EDUCATIVO - NO PARA EXPLOTACIÓN ⚠️**
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗GitHub PoC★ 13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗GitHub PoC★ 32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
Windows Kernel Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗GitHub PoC★ 14
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗GitHub PoC★ 6
PoC Exploit CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
cyhe50/cve-2025-32434-poc
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RIESGO
abrir ↗GitHub PoC★ 24
redpack-kr/CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC
Alex-Acero-Security/CVE-2024-48910-POC
DOMPurify vulnerable to tampering by prototype polution
48RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-48703 é uma vulnerabilidade de Execução Remota de Código (RCE) no módulo filemanager de um painel de hospedagem web (por exemplo, cPanel). Ocorre devido ao tratamento de entrada não sanitizado na função acc=changePerm, que permite que um atacante injete e execute comandos.
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir ↗GitHub PoC
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
76RIESGO
abrir ↗GitHub PoC★ 1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir ↗GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RIESGO
abrir ↗GitHub PoC★ 2
AstrBot老版本RCE
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us
41RIESGO
abrir ↗GitHub PoC
Detection for CVE-2025-34299
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗GitHub PoC★ 5
Wh04m1001/CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC
harekrishnarai/CVE-2024-23897-test-windows
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
Vulnerability for Xwiki
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RIESGO
abrir ↗GitHub PoC★ 2
Mitchellzhou1/CVE-2024-48910-PoC
DOMPurify vulnerable to tampering by prototype polution
48RIESGO
abrir ↗GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗GitHub PoC
Exploit and test stand for CVE-2025-2945
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗GitHub PoC★ 1
check if vulnerable python-django version to CVE-2025-64459 bug
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir ↗GitHub PoC★ 1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗GitHub PoC
Ghstxz/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.