Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
CVE-2024-32113-Apache-OFBiz<18.12.13-Exploit
CVE-2024-32113CRITICALbajo ataque09 oct 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 oct 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
lastvocher/Hikvision-CVE-2017-7921-decryptor
CVE-2017-7921CRITICALbajo ataque08 oct 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC
Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1
CVE-2025-44823CRITICAL07 oct 2025
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
53RIESGO
abrir
GitHub PoC1
Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security research
CVE-2024-39309CRITICAL07 oct 2025
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
53RIESGO
abrir
GitHub PoC
Remote Code Execution PoC for Apache 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware07 oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
hybinn/CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware06 oct 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
compiled poc binary
CVE-2024-30088HIGHbajo ataqueransomware06 oct 2025
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
GitHub PoC
exploit for CVE-2018-16763
CVE-2018-1676305 oct 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
shoucheng3/apache__struts_CVE-2020-17530_2-5-25
CVE-2020-17530CRITICALbajo ataque05 oct 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC
WP-CVE-2025-6934 | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL05 oct 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC
Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)
CVE-2020-1472MEDIUMbajo ataqueransomware04 oct 2025
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
An Python Exp For "GeoServer"
CVE-2024-36401CRITICALbajo ataque04 oct 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC12
Arbitrary Function Call Exploit using the ThrottleStop driver
CVE-2025-7771HIGH03 oct 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
CVE-2025-9242CRITICALbajo ataque01 oct 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RIESGO
abrir
GitHub PoC
CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)
CVE-2024-3400CRITICALbajo ataqueransomware01 oct 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware30 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALbajo ataque30 sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALbajo ataque30 sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHbajo ataqueransomware30 sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
GitHub PoC1
Detection for CVE-2025-41244
CVE-2025-41244HIGHbajo ataque30 sep 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RIESGO
abrir
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALbajo ataque30 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALbajo ataque30 sep 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALbajo ataqueransomware29 sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 sep 2025
Remote Code Execution & File Deletion in Asset Uploads
48RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALbajo ataqueransomware29 sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHbajo ataqueransomware28 sep 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RIESGO
abrir
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware27 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 sep 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
anteriorpágina 114 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.