Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC198
Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
CVE-2025-32756CRITICALbajo ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir
GitHub PoC3
rasool13x/exploit-CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHbajo ataque05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC104
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHbajo ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
A repository used for Hackthebox ServMon Machine
CVE-2019-20085HIGHbajo ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC33
CVE-2025-4123 - Grafana Tool
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
MantisToboggan-git/CVE-2025-4632-POC
CVE-2025-4632CRITICALbajo ataque04 jun 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RIESGO
abrir
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-1284004 jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC3
CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALbajo ataque04 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC2
r007sec/CVE-2024-53677
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)
CVE-2019-721403 jun 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
GitHub PoC1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 jun 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC3
pgAdmin Proof of Concept
CVE-2025-2945CRITICAL03 jun 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
GitHub PoC5
Detection for CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque03 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
imbas007/CVE-2025-4123-template
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-468803 jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir
GitHub PoC
MS08-067 | CVE-2008-4250
CVE-2008-4250CRITICALbajo ataque02 jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC3
A reflected cross-site scripting (XSS) vulnerability exists in MailEnable Webmail due to improper user input sanitization in the failure.aspx. This allows a remote attacker to inject arbitrary JavaScript code via a crafted URL, which is then reflected in the server's response and executed in the context of the user's browser session.
CVE-2025-44148CRITICAL02 jun 2025
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via
75RIESGO
abrir
GitHub PoC3
CTY-Research-1/CVE-2025-32432-PoC
CVE-2025-32432CRITICALbajo ataque01 jun 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC2
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL01 jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
GitHub PoC1
fatkz/CVE-2025-27590
CVE-2025-27590CRITICAL31 may 2025
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr
53RIESGO
abrir
GitHub PoC
Vbullettin RCE - CVE-2025-48827
CVE-2025-48827CRITICAL31 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
GitHub PoC1
This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.
CVE-2025-3248CRITICALbajo ataqueransomware31 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC3
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
CVE-2024-9264CRITICAL31 may 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC67
Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)
CVE-2025-30397HIGHbajo ataque31 may 2025
Scripting Engine Memory Corruption Vulnerability
76RIESGO
abrir
GitHub PoC
This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.
CVE-2018-15473MEDIUM30 may 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.
CVE-2017-0144HIGHbajo ataqueransomware30 may 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
anteriorpágina 145 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.