Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
The exploit code for CVE-2025-43300.
CVE-2025-43300CRITICALbajo ataque22 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC
Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.
CVE-2016-5195HIGHbajo ataque22 ago 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1
Some poorly crafted exploit scripts
CVE-2025-24893CRITICALbajo ataque22 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.
CVE-2025-27519CRITICAL22 ago 2025
Cognita Arbitrary File Write
48RIESGO
abrir
GitHub PoC1
Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)
CVE-2008-144722 ago 2025
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
GitHub PoC
Telerik CVE-2019-18935 Vulnerability Scanner
CVE-2019-18935CRITICALbajo ataqueransomware22 ago 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC1
Kryptoenix/CVE-2025-47987_PoC
CVE-2025-47987HIGH22 ago 2025
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Customized this for my own use
CVE-2023-41892CRITICAL21 ago 2025
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC1
CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool
CVE-2023-35078CRITICALbajo ataqueransomware21 ago 2025
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC
This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs.
CVE-2025-8088HIGHbajo ataque21 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Exploit code for CVE-2015-8351
CVE-2015-835121 ago 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
GitHub PoC
shoucheng3/spring-projects__spring-framework_CVE-2022-22965_5-2-19-RELEASE
CVE-2022-22965CRITICALbajo ataque20 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The assessment will focus on exploiting a specific, real-world vulnerability (CVE-2021-29447) to achieve initial access.
CVE-2021-29447HIGH20 ago 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC3
A Windows GUI tool demonstrating a proof-of-concept archive traversal technique related to CVE-2025-8088 using WinRAR’s CLI. Allows building crafted RAR files with payload + decoy files through an easy modern interface. For educational and security-research purposes only.
CVE-2025-8088HIGHbajo ataque20 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
shoucheng3/asf__commons-text_CVE-2022-42889_1-9
CVE-2022-4288920 ago 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
shoucheng3/apache__flink_CVE-2020-17519_1-11-2
CVE-2020-17519CRITICALbajo ataque20 ago 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC
Ianthinus/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware20 ago 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-6
CVE-2022-22947CRITICALbajo ataque20 ago 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
harshitvarma05/CVE-2025-31324-Exploits
CVE-2025-31324CRITICALbajo ataqueransomware20 ago 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1-8-13
CVE-2022-44262CRITICAL20 ago 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RIESGO
abrir
GitHub PoC
This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.
CVE-2018-7600CRITICALbajo ataqueransomware20 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
replicatorbot/CVE-2025-48384-POC
CVE-2025-48384HIGHbajo ataque20 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
replicatorbot/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque20 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
shoucheng3/jmrozanec__cron-utils_CVE-2021-41269_9-1-5
CVE-2021-41269CRITICAL20 ago 2025
Unauthenticated remote code injection in cron-utils
48RIESGO
abrir
GitHub PoC
shoucheng3/xwiki__xwiki-commons_CVE-2023-29528_14-9-rc-1
CVE-2023-29528CRITICAL20 ago 2025
Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml
48RIESGO
abrir
GitHub PoC3
Exploit for CVE-2025-5777: Citrix NetScaler Memory Disclosure (CitrixBleed 2)
CVE-2025-5777CRITICALbajo ataqueransomware20 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
shoucheng3/xwiki__xwiki-commons_CVE-2023-29201_14-5
CVE-2023-29201CRITICAL20 ago 2025
org.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability
48RIESGO
abrir
GitHub PoC
R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
CVE-2025-29927CRITICAL19 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
www-spam/CVE-2024-53900
CVE-2024-53900CRITICAL19 ago 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
CVE-2023-49109CRITICAL19 ago 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir
anteriorpágina 123 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.