Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 sep 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware27 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
Scans target to see if its vulnerable to CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware26 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC2
CVE-2024-6387 and more Checker and Exploiter - Reverse/Bind-Shell Support.
CVE-2024-6387HIGH26 sep 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
Analyzing CVE-2023-36802 (mskssrv.sys) - object type confusion bug
CVE-2023-36802HIGHbajo ataque26 sep 2025
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC8
CVE-2025-8088 exploit C++ impl
CVE-2025-8088HIGHbajo ataque25 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Example script demonstrating a weak PRNG, CVE-2008-0166
CVE-2008-016625 sep 2025
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir
GitHub PoC
CVE-2025-49132
CVE-2025-49132CRITICAL25 sep 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
GitHub PoC6
CVE-2025-20352 SNMP Exposure Check (onesixtyone + parser)
CVE-2025-20352HIGHbajo ataque25 sep 2025
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
83RIESGO
abrir
GitHub PoC1
JS Archive List <= 6.1.5 - Unauthenticated SQL Injection
CVE-2025-54726CRITICAL25 sep 2025
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RIESGO
abrir
GitHub PoC
CVE-2017-5638- PoC
CVE-2017-5638CRITICALbajo ataqueransomware25 sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Microsoft HEIF Extension (msheif_store.dll) OOB-read
CVE-2025-62821CRITICAL25 sep 2025
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc
48RIESGO
abrir
GitHub PoC
CVE-2025-34100 test
CVE-2025-34100CRITICAL24 sep 2025
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)
CVE-2018-7600CRITICALbajo ataqueransomware24 sep 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
iteride/CVE-2025-2294
CVE-2025-2294CRITICAL24 sep 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
CVE-2025-57174 Unauthenticated Remote Command Execution
CVE-2025-57174CRITICAL24 sep 2025
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p
48RIESGO
abrir
GitHub PoC
RCE project
CVE-2017-1261124 sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir
GitHub PoC2
the task from C*****k
CVE-2025-32433CRITICALbajo ataque24 sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.
CVE-2024-32002CRITICAL24 sep 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC2
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-56819CRITICAL24 sep 2025
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RIESGO
abrir
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2025-32463, a vulnerability in sudo allowing a chroot escape to achieve local privilege escalation.
CVE-2025-32463CRITICALbajo ataque24 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-
CVE-2024-21413CRITICALbajo ataque23 sep 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Detection for CVE-2025-26399
CVE-2025-26399CRITICALbajo ataque23 sep 2025
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
100RIESGO
abrir
GitHub PoC
dadosneurais/cve-2023-3824
CVE-2023-3824CRITICAL23 sep 2025
Buffer overflow and overread in phar_dir_read()
48RIESGO
abrir
GitHub PoC2
AI修复生成的CVE-2025-32432的poc
CVE-2025-32432CRITICALbajo ataque23 sep 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC
Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)
CVE-2025-29927CRITICAL23 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL23 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
iteride/CVE-2025-1974
CVE-2025-1974CRITICAL23 sep 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Michaael01/LetsDefend--SOC-342-CVE-2025-53770-SharePoint-Exploit-ToolShell
CVE-2025-53770CRITICALbajo ataqueransomware23 sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Proof-of-concept script for CVE-2020-3452 — Cisco ASA/FTD Path Traversal vulnerability. Supports automated extraction of known file targets with a hard limit on successful downloads for safety. Intended for authorized security testing and research purposes only.
CVE-2020-3452HIGHbajo ataque23 sep 2025
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
anteriorpágina 115 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.