Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
cuijiung/log4j-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RIESGO
abrir
GitHub PoC
CVE-2024-32113 & CVE-2024-38856
CVE-2024-32113CRITICALbajo ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC
Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE
CVE-2022-36934CRITICAL11 jul 2025
An integer overflow in WhatsApp could result in remote code execution in an established video call.
48RIESGO
abrir
GitHub PoC
p1026/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC1
PoC dockerfile image for CVE-2025-48384
CVE-2025-48384HIGHbajo ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALbajo ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
altm4n/cve-2025-48384
CVE-2025-48384HIGHbajo ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC14
This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.
CVE-2017-0144HIGHbajo ataqueransomware10 jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
漏洞测试
CVE-2025-48384HIGHbajo ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
greatyy/CVE-2025-48384-p
CVE-2025-48384HIGHbajo ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Exploit for CVE-2025-32023
CVE-2025-32023HIGH10 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RIESGO
abrir
GitHub PoC
CVE-2025-48384
CVE-2025-48384HIGHbajo ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
altm4n/cve-2025-48384-hub
CVE-2025-48384HIGHbajo ataque10 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC30
CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)
CVE-2025-5777CRITICALbajo ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-25600
CVE-2024-25600CRITICAL10 jul 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware10 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-27954
CVE-2024-27954CRITICAL10 jul 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RIESGO
abrir
GitHub PoC98
watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
CVE-2025-25257CRITICALbajo ataque10 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
Citrix NetScaler Memory Leak PoC
CVE-2025-5777CRITICALbajo ataqueransomware10 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC18
CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when a user extracts a specially crafted
CVE-2025-6218HIGHbajo ataque10 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
CVE-2025-6554 PoC
CVE-2025-6554HIGHbajo ataque10 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC8
ekkoo-z/CVE-2019-18935-bypasswaf
CVE-2019-18935CRITICALbajo ataqueransomware09 jul 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC6
WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)
CVE-2025-34077CRITICAL09 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
GitHub PoC1
ghostn4444/POC-CVE-2025-6554
CVE-2025-6554HIGHbajo ataque09 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC1
0xb0rn3/CVE-2025-32463-EXPLOIT
CVE-2025-32463CRITICALbajo ataque09 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
rpgsec/Roundcube-CVE-2024-42008-POC
CVE-2024-42008CRITICAL09 jul 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RIESGO
abrir
GitHub PoC
CitrixBleed2 powershell version
CVE-2025-5777CRITICALbajo ataqueransomware09 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
ppd520/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
kallydev/cve-2025-48384-hook
CVE-2025-48384HIGHbajo ataque09 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
anteriorpágina 136 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.