Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
pouriam23/CVE-2024-12583
CVE-2024-12583CRITICAL23 may 2025
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
48RIESGO
abrir
GitHub PoC
encrypter15/CVE-2025-30400
CVE-2025-30400HIGHbajo ataque23 may 2025
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
Unauthenticated Arbitrary File Read via Absolute Path
CVE-2025-46822HIGH23 may 2025
Unauthenticated Arbitrary File Read via Absolute Path
56RIESGO
abrir
GitHub PoC
Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156
CVE-2021-3156HIGHbajo ataque23 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab
CVE-2025-29927CRITICAL23 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC5
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CVE-2025-31161CRITICALbajo ataqueransomware23 may 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-9463
CVE-2024-9463CRITICALbajo ataque22 may 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir
GitHub PoC1
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
CVE-2025-4322CRITICAL22 may 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir
GitHub PoC2
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
CVE-2024-21762CRITICALbajo ataqueransomware22 may 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC2
Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.
CVE-2025-31200CRITICALbajo ataque22 may 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
GitHub PoC56
Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF
CVE-2025-4123HIGH22 may 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
GitHub PoC5
Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474
CVE-2024-0012CRITICALbajo ataqueransomware21 may 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
GitHub PoC
CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."
CVE-2021-34527HIGHbajo ataqueransomware21 may 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
RdBBB3/SHELL-POC-CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque21 may 2025
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
CVE-2025-5058CRITICAL21 may 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()
48RIESGO
abrir
GitHub PoC1
IndominusRexes/CVE-2025-4322-Exploit
CVE-2025-4322CRITICAL20 may 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL20 may 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
GitHub PoC
PoC for CVE-2025-47646 - WordPress PSW Front-end Login Registration Plugin ≤ 1.12 Unauthenticated Privilege Escalation
CVE-2025-47646CRITICAL20 may 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RIESGO
abrir
GitHub PoC
CVE-2024-53677
CVE-2024-53677CRITICAL20 may 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.
CVE-2024-3094CRITICAL20 may 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC2
PoC and vulnerability report for CVE-2025-47827.
CVE-2025-47827MEDIUMbajo ataque20 may 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
63RIESGO
abrir
GitHub PoC
Automated path traversal testing tool for Grafana plugin endpoints using curl and Bash.
CVE-2021-43798HIGHbajo ataque19 may 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes
CVE-2025-24054MEDIUMbajo ataque19 may 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on the server. By supplying a crafted URL that hosts a reverse shell payload, an attacker can gain command execution.
CVE-2019-9978MEDIUMbajo ataque19 may 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db
CVE-2011-076219 may 2025
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RIESGO
abrir
GitHub PoC
Mitel MiCollab Authentication Bypass to Arbitrary File Read
CVE-2024-41713CRITICALbajo ataqueransomware18 may 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
GitHub PoC4
Designed for Demonstration of Deep Exploitation.
CVE-2025-32756CRITICALbajo ataque18 may 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC200
CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
CVE-2025-31200CRITICALbajo ataque17 may 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
GitHub PoC
tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
CVE-2020-1472MEDIUMbajo ataqueransomware17 may 2025
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 may 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
anteriorpágina 147 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.