Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
CVE-2011-436716 ago 2025
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RIESGO
abrir
GitHub PoC1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
CVE-2018-742216 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC1
Ash1996x/CVE-2025-50154-Aggressor-Script
CVE-2025-50154MEDIUM16 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
CVE-2023-37582CRITICAL16 ago 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
CVE-2025-6934CRITICAL16 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
CVE-2025-8088HIGHbajo ataque15 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
0xr2r/CVE-2017-11317-auto-exploit-
CVE-2017-11317CRITICALbajo ataque15 ago 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
GitHub PoC
hlc23/CVE-2024-5932-web-ui
CVE-2024-5932CRITICAL15 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
GitHub PoC4
Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports single/multi-target scanning, and includes a harmless local PoC marker.
CVE-2025-20265CRITICAL15 ago 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RIESGO
abrir
GitHub PoC2
MailPoet Newsletters <= Arbitrary File Upload (exploiter)
CVE-2014-472515 ago 2025
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RIESGO
abrir
GitHub PoC4
A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.
CVE-2024-3660CRITICAL15 ago 2025
Arbitrary code injection vulnerability in Keras framework < 2.13
48RIESGO
abrir
GitHub PoC110
PoC and technical details of CVE-2025-24204
CVE-2025-24204CRITICAL15 ago 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RIESGO
abrir
GitHub PoC22
sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324
CVE-2025-31324CRITICALbajo ataqueransomware15 ago 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
Exploration of the Follina (CVE-2022-30190) Microsoft Office vulnerability, including a detailed analysis, proof-of-concept exploitation in a controlled lab, and mitigation strategies. For educational and research purposes only.
CVE-2022-30190HIGHbajo ataqueransomware14 ago 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Kento-Sec/CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque14 ago 2025
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
n0m-d/CVE-2018-0114-Go
CVE-2018-011414 ago 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
CVE-2025-53770 - SharePoint
CVE-2025-53770CRITICALbajo ataqueransomware14 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC56
Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088
CVE-2025-8088HIGHbajo ataque14 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
okkotsu1/CVE-2024-47533
CVE-2024-47533CRITICAL14 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir
GitHub PoC54
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
CVE-2025-50154MEDIUM13 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
CVE-2023-32434HIGHbajo ataque13 ago 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RIESGO
abrir
GitHub PoC7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque13 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC71
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)
CVE-2025-8088HIGHbajo ataque13 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Dissecting CVEin Chrome
CVE-2025-5419HIGHbajo ataque13 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RIESGO
abrir
GitHub PoC
benguelmas/cve-2017-0143
CVE-2017-0143HIGHbajo ataqueransomware13 ago 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC1
PoC of CVE-2025-47533 Clobber RCE
CVE-2024-47533CRITICAL13 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir
GitHub PoC
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
CVE-2025-24893CRITICALbajo ataque13 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
CVE-2025-53770CRITICALbajo ataqueransomware13 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
zenzue/CVE-2025-50154
CVE-2025-50154MEDIUM13 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
CVE-2025-50428CRITICAL13 ago 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RIESGO
abrir
anteriorpágina 125 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.