Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecución remota de código (RCE) en Apache Tomcat (CVE-2025-24813).
CVE-2025-24813CRITICALbajo ataque08 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware08 sep 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
CVE-2024-6387
CVE-2024-6387HIGH08 sep 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC2
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains how attackers can escape container boundaries, compromise AI workloads, and how tools like Sentinel can detect and mitigate the threat
CVE-2025-23266CRITICAL07 sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir
GitHub PoC
CTY-Research-1/CVE-2025-47812_Lab_environment
CVE-2025-47812CRITICALbajo ataque07 sep 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
CVE-2019-905307 sep 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC3
PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.
CVE-2025-32433CRITICALbajo ataque07 sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC3
This is CVE-2025-53690 Analysis Documents.
CVE-2025-53690CRITICALbajo ataque07 sep 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
GitHub PoC9
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
CVE-2025-7771HIGH07 sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC
MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
CVE-2017-5638CRITICALbajo ataqueransomware06 sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
CVE-2022-44262CRITICAL06 sep 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RIESGO
abrir
GitHub PoC
whisperer1290/CVE-2025-54309__Enhanced_exploit
CVE-2025-54309CRITICALbajo ataque06 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
cve-2025-33073/cve-2025-33073
CVE-2025-33073HIGHbajo ataque06 sep 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC2
FOGProject Authentication bypass CVE-2025-58443 Exploit
CVE-2025-58443CRITICAL06 sep 2025
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir
GitHub PoC
oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
CVE-2013-3900MEDIUMbajo ataque06 sep 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
tranphuc2005/CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware06 sep 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC2
PoC for CVE-2015-5736
CVE-2015-573606 sep 2025
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RIESGO
abrir
GitHub PoC1
This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC
Python script to execute CVE-2025-24071
CVE-2025-24071MEDIUM05 sep 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal + RCE (CVE-2021-42013) en servidores mal configurados.
CVE-2021-42013CRITICALbajo ataqueransomware05 sep 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation
CVE-2025-49388CRITICAL05 sep 2025
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
48RIESGO
abrir
GitHub PoC
andwati/CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque05 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
blackcat4347/CVE-2025-32463_PoC
CVE-2025-32463CRITICALbajo ataque05 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
Educational, non-functional Linux kernel exploit template for CVE-2024-1086 — lab-only security research and teaching (use in controlled VMs only).
CVE-2024-1086HIGHbajo ataqueransomware04 sep 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC5
Detection for CVE-2025-53690
CVE-2025-53690CRITICALbajo ataque04 sep 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
GitHub PoC
Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots, commands, and detection logic.
CVE-2025-32709HIGHbajo ataque04 sep 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).
CVE-2025-57819CRITICALbajo ataque04 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC134
FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2
CVE-2025-24204CRITICAL04 sep 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RIESGO
abrir
anteriorpágina 119 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.