Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework integration
CVE-2018-19323CRITICALbajo ataqueransomware27 ago 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RIESGO
abrir
GitHub PoC
a1ex-var1amov/ctf-cve-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware26 ago 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC1
POWERSHEL script to check if your device is affected or no
CVE-2025-8088HIGHbajo ataque26 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
CVE-2025-8088HIGHbajo ataque26 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVE-2025-34030CRITICAL26 ago 2025
sar2html OS Command Injection
75RIESGO
abrir
GitHub PoC
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893CRITICALbajo ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
CVE-2025-24893CRITICALbajo ataque26 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC12
An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.
CVE-2025-8088HIGHbajo ataque26 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
Real4XoR/CVE-2019-6693
CVE-2019-6693MEDIUMbajo ataqueransomware26 ago 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir
GitHub PoC
a1ex-var1amov/ctf-cve-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware25 ago 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC3
Apache Struts2 CVE-2017-5638 (Safe Educational Demo)
CVE-2017-5638CRITICALbajo ataqueransomware25 ago 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC95
mistymntncop/CVE-2025-5419
CVE-2025-5419HIGHbajo ataque25 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RIESGO
abrir
GitHub PoC11
zenzue/CVE-2025-9074
CVE-2025-9074CRITICAL25 ago 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC
PoC
CVE-2025-48384HIGHbajo ataque25 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
TamatahYT/CVE-2017-8481
CVE-2017-848125 ago 2025
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
GitHub PoC2
Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.
CVE-2024-4367MEDIUM25 ago 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC28
watchtowrlabs/watchTowr-vs-CrushFTP-Authentication-Bypass-CVE-2025-54309
CVE-2025-54309CRITICALbajo ataque25 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC
his project demonstrates the exploitation of the vsFTPd 2.3.4 backdoor vulnerability (CVE-2011-2523) using Metasploitable 2 and Kali Linux with Metasploit. It includes reconnaissance, exploitation, and defensive measures, with a detailed report and lab setup for learning ethical hacking and security best practices.
CVE-2011-252325 ago 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
A research regarding the exisiting CVE exploit : CVE-2021-3156(Sudo BufferOverflow)
CVE-2021-3156HIGHbajo ataque25 ago 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC114
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALbajo ataque24 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC4
POC of CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque24 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Quick and easy exploitation of CVE-2024-4956 for LFI.
CVE-2024-4956HIGH24 ago 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
GitHub PoC39
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then WebKit(CVE-2025-24201) and Core Media(CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
CVE-2025-24085CRITICALbajo ataque23 ago 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RIESGO
abrir
GitHub PoC1
POC exploit for CVE-2025-33053 (external control of file execution path in URL file)
CVE-2025-33053HIGHbajo ataque23 ago 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Este repositório contém um script de prova de conceito (PoC) que demonstra uma vulnerabilidade crítica encontrada no plugin Simple File List para WordPress.
CVE-2020-36847CRITICAL23 ago 2025
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir
GitHub PoC
donmedfor/CVE-2015-3306
CVE-2015-330623 ago 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
A PHP CGI Vulnerability Scanner for CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware23 ago 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
2025年8月20日に公開されたDockerDesktopの脆弱性(対策済み)を実証する
CVE-2025-9074CRITICAL23 ago 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC
Sequelize Sql Injection 취약점 구현
CVE-2023-25813CRITICAL23 ago 2025
SQL Injection via replacements in sequelize
48RIESGO
abrir
GitHub PoC2
PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.
CVE-2025-27519CRITICAL22 ago 2025
Cognita Arbitrary File Write
48RIESGO
abrir
anteriorpágina 122 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.