Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.279 exploits
GitHub PoC2
AstrBot老版本RCE
CVE-2025-55449HIGH11 nov 2025
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us
41RIESGO
abrir
GitHub PoC2
CVE-2025-48703 é uma vulnerabilidade de Execução Remota de Código (RCE) no módulo filemanager de um painel de hospedagem web (por exemplo, cPanel). Ocorre devido ao tratamento de entrada não sanitizado na função acc=changePerm, que permite que um atacante injete e execute comandos.
CVE-2025-48703CRITICALbajo ataque11 nov 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
GitHub PoC8
CVE-2025-55315 PoC Exploit
CVE-2025-55315CRITICAL11 nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RIESGO
abrir
GitHub PoC1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
CVE-2025-11953CRITICALbajo ataque11 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC
CVE-2025-21042
CVE-2025-21042HIGHbajo ataque11 nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
76RIESGO
abrir
GitHub PoC2
Mitchellzhou1/CVE-2024-48910-PoC
CVE-2024-48910CRITICAL11 nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RIESGO
abrir
GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
CVE-2025-25257CRITICALbajo ataque11 nov 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
Detection for CVE-2025-34299
CVE-2025-34299CRITICAL11 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
GitHub PoC
Vulnerability for Xwiki
CVE-2024-31982CRITICAL11 nov 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RIESGO
abrir
GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
CVE-2024-51378CRITICALbajo ataqueransomware11 nov 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
GitHub PoC1
check if vulnerable python-django version to CVE-2025-64459 bug
CVE-2025-64459CRITICAL10 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC
Exploit and test stand for CVE-2025-2945
CVE-2025-2945CRITICAL10 nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
GitHub PoC
Ghstxz/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque10 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
CVE-2025-6440CRITICAL10 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
CVE-2025-24054MEDIUMbajo ataque09 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC12
CVE-2025-6554
CVE-2025-6554HIGHbajo ataque09 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC
n0m-d/CVE-2021-40438-POC
CVE-2021-40438CRITICALbajo ataque09 nov 2025
mod_proxy SSRF
100RIESGO
abrir
GitHub PoC
letsr00t/-CVE-2019-18634-sudo-pwfeedback
CVE-2019-1863408 nov 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
l1nuxkid/CVE-2025-32433-exploit
CVE-2025-32433CRITICALbajo ataque08 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC9
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CVE-2025-11749CRITICAL08 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RIESGO
abrir
GitHub PoC10
Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.
CVE-2024-9680CRITICALbajo ataqueransomware07 nov 2025
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RIESGO
abrir
GitHub PoC
Tomcat - PUT Method
CVE-2017-12615HIGHbajo ataqueransomware07 nov 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHbajo ataque07 nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RIESGO
abrir
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHbajo ataque07 nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RIESGO
abrir
GitHub PoC4
demo CVE-2019-2215 (Bad Binder) for Android Q
CVE-2019-2215HIGHbajo ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC2
This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.
CVE-2024-21413CRITICALbajo ataque06 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2025-54782
CVE-2025-54782CRITICAL06 nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RIESGO
abrir
GitHub PoC
rockmelodies/django_sqli_target_CVE-2025-64459
CVE-2025-64459CRITICAL06 nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
CVE-2024-4040CRITICALbajo ataque05 nov 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC8
CVE-2025-53690 POC
CVE-2025-53690CRITICALbajo ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
anteriorpágina 110 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.