Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
Educational, non-functional Linux kernel exploit template for CVE-2024-1086 — lab-only security research and teaching (use in controlled VMs only).
CVE-2024-1086HIGHbajo ataqueransomware04 sep 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC134
FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2
CVE-2025-24204CRITICAL04 sep 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RIESGO
abrir
GitHub PoC1
vulnerability in NGINX servers (versions 0.6.18–1.20.0). The scripts aim to cause a Denial of Service (DoS) by sending malicious DNS responses, with enhancements to bypass firewalls.
CVE-2021-2301704 sep 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC
neverhavenamee/CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque04 sep 2025
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC
Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots, commands, and detection logic.
CVE-2025-32709HIGHbajo ataque04 sep 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
CVE-2025-9074CRITICAL03 sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC
This repository provides a modified version of the original CVE-2017-6074 exploit (use-after-free in the Linux kernel DCCP subsystem), designed only to demonstrate Denial of Service (DoS) impact. An authenticated local user can trigger a kernel panic, causing a total loss of system availability.
CVE-2017-607403 sep 2025
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir
GitHub PoC
CVE-2025-3248
CVE-2025-3248CRITICALbajo ataqueransomware03 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC2
Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability
CVE-2025-54309CRITICALbajo ataque03 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC1
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
CVE-2016-15042CRITICAL03 sep 2025
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
This is a PoC for the CVE-2025-24813 and tested in different environments.
CVE-2025-24813CRITICALbajo ataque03 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC11
b0ySie7e/CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque03 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
Reproducible lab for CVE-2020-0610 (BlueGate) - Windows RD Gateway UDP/DTLS remote code execution vulnerability. Includes PowerShell scripts, setup guide, and nuclei template validation examples.
CVE-2020-061003 sep 2025
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RIESGO
abrir
GitHub PoC2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL02 sep 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
CVE-2025-23266CRITICAL02 sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir
GitHub PoC
Python3 port of the original Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
CVE-2019-1094502 sep 2025
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
GitHub PoC1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CVE-2024-51568CRITICAL02 sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir
GitHub PoC1
Version detection PowerShell
CVE-2025-7775CRITICALbajo ataque02 sep 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir
GitHub PoC1
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
CVE-2024-47875CRITICAL02 sep 2025
DOMPurify nesting-based mXSS
48RIESGO
abrir
GitHub PoC1
a proof of concept of CVE-2024-53677
CVE-2024-53677CRITICAL01 sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
CVE-2025-34300CRITICAL01 sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir
GitHub PoC6
FreePBX SQL Injection Exploit
CVE-2025-57819CRITICALbajo ataque01 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC1
HTML cache poisoning through unsafe reflections
CVE-2025-53693CRITICAL01 sep 2025
HTML Cache Poisoning through Unsafe Reflections
53RIESGO
abrir
GitHub PoC17
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC20
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALbajo ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RIESGO
abrir
GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
CVE-2025-2776CRITICALbajo ataque31 ago 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir
GitHub PoC2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALbajo ataque31 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir
GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
CVE-2021-41773HIGHbajo ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Detection for CVE-2025-4427 and CVE-2025-4428
CVE-2025-4427MEDIUMbajo ataque31 ago 2025
Authentication Bypass
100RIESGO
abrir
anteriorpágina 120 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.