Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.953exploits catalogados
32.194CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
PoC for CVE-2024-47575
CVE-2024-47575CRITICALbajo ataque19 jul 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
GitHub PoC2
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
CVE-2025-7795HIGH19 jul 2025
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RIESGO
abrir
GitHub PoC7
💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection
CVE-2025-49113CRITICALbajo ataque19 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2025-41646
CVE-2025-41646CRITICAL19 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RIESGO
abrir
GitHub PoC
alm6no5/CVE-2024-20767
CVE-2024-20767HIGHbajo ataque19 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
Joelp03/CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque18 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALbajo ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RIESGO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHbajo ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RIESGO
abrir
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHbajo ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHbajo ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
malaya-m/cve-2013-3900-remediation-report
CVE-2013-3900MEDIUMbajo ataque16 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC
CVE-2025-53833
CVE-2025-53833CRITICAL16 jul 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RIESGO
abrir
GitHub PoC2
(PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
CVE-2025-27210HIGH16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RIESGO
abrir
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
CVE-2022-3541116 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir
GitHub PoC
Floodnut/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
CVE-2025-48384HIGHbajo ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC1
krypton-0x00/CVE-2025-32463-Chwoot-POC
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
Kalidas-7/CVE-2019-9053
CVE-2019-905316 jul 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC2
joelczk/CVE-2025-52688
CVE-2025-52688CRITICAL16 jul 2025
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RIESGO
abrir
GitHub PoC
Detection for CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque16 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC2
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
anteriorpágina 133 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.