Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 may 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
GitHub PoC200
CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
CVE-2025-31200CRITICALbajo ataque17 may 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
GitHub PoC
CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
CVE-2022-41082HIGHbajo ataqueransomware16 may 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
PenguinCabinet/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM16 may 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability
CVE-2021-4034HIGHbajo ataque16 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC2
WordPress PSW Front-end Login &amp; Registration Plugin <= 1.12 is vulnerable to Broken Authentication
CVE-2025-47646CRITICAL16 may 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RIESGO
abrir
GitHub PoC2
GadaLuBau1337/CVE-2025-32583
CVE-2025-32583CRITICAL16 may 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RIESGO
abrir
GitHub PoC4
Ivanti EPMM Pre-Auth RCE Chain
CVE-2025-4428HIGHbajo ataque16 may 2025
Remote Code Execution
100RIESGO
abrir
GitHub PoC1
(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload
CVE-2024-51793CRITICAL15 may 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment
CVE-2023-20198CRITICALbajo ataque15 may 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC1
CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass
CVE-2025-4094CRITICAL15 may 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RIESGO
abrir
GitHub PoC2
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)
CVE-2025-4094CRITICAL15 may 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RIESGO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2025-3605
CVE-2025-3605CRITICAL15 may 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
GitHub PoC2
演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。
CVE-2025-29927CRITICAL15 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC11
watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
CVE-2025-4427MEDIUMbajo ataque15 may 2025
Authentication Bypass
100RIESGO
abrir
GitHub PoC
fatkz/CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque14 may 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC
This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.
CVE-2015-330614 may 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!
CVE-2021-4034HIGHbajo ataque14 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC29
encrypter15/CVE-2025-29824
CVE-2025-29824HIGHbajo ataqueransomware14 may 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
MandipJoshi/CVE-2021-3560
CVE-2021-3560HIGHbajo ataque13 may 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
CVE-2025-3248CRITICALbajo ataqueransomware13 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL13 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.
CVE-2022-21661HIGH13 may 2025
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC55
WHW0x455/CVE-2023-41992
CVE-2023-41992HIGHbajo ataque12 may 2025
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RIESGO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2025-4603CRITICAL12 may 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RIESGO
abrir
GitHub PoC
shishirpandey18/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque12 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
使用PowsrShell掃描CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware12 may 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
CVE-2023-37582CRITICAL12 may 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC3
rebelle3/cve-2017-7117
CVE-2017-711712 may 2025
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir
GitHub PoC
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass
CVE-2025-0411HIGHbajo ataque11 may 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
anteriorpágina 148 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.