Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC1
PoC for CVE-2025-2011 - SQLi in Depicter plugin <= 3.6.1
CVE-2025-2011HIGH06 may 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
GitHub PoC1
Commvault Remote Code Execution (CVE-2025-34028) NSE
CVE-2025-34028CRITICALbajo ataque06 may 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
GitHub PoC
Shellshock Vulnerability Scanner
CVE-2014-6271CRITICALbajo ataque05 may 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
CVE-2025-4524 - Unauthenticated madara-core Wordpress theme LFI
CVE-2025-4524CRITICAL05 may 2025
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RIESGO
abrir
GitHub PoC1
Scanner and exploit for CVE-2025-3248
CVE-2025-3248CRITICALbajo ataqueransomware05 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC1
ductink98lhp/analyze-Exploit-CVE-2023-22518-Confluence
CVE-2023-22518CRITICALbajo ataqueransomware05 may 2025
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RIESGO
abrir
GitHub PoC5
This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions and upload malicious files. This can lead to Remote Code Execution (RCE) when the uploaded payload is triggered.
CVE-2024-21546CRITICAL05 may 2025
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through
48RIESGO
abrir
GitHub PoC2
Artemir7/CVE-2025-24893-EXP
CVE-2025-24893CRITICALbajo ataque05 may 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
CCIEVoice2009/CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware04 may 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected
CVE-2024-49138HIGHbajo ataque04 may 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
This CVE - PoC about information on the CVEs I found.
CVE-2025-47226MEDIUM03 may 2025
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RIESGO
abrir
GitHub PoC
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
CVE-2025-31125MEDIUMbajo ataque03 may 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
GitHub PoC3
This repository includes everything needed to run a PoC exploit for CVE-2025-32375 in a Docker environment. It runs the latest vulnerable version of BentoML (1.4.7).
CVE-2025-32375CRITICAL03 may 2025
Insecure Deserialization leads to RCE in BentoML's runner server
75RIESGO
abrir
GitHub PoC1
olimpiofreitas/CVE-2025-29927-scanner
CVE-2025-29927CRITICAL03 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.
CVE-2025-32433CRITICALbajo ataque03 may 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
ByteMe1001/CVE-2020-13151-POC-Aerospike-Server-Host-Command-Execution-RCE-
CVE-2020-1315103 may 2025
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
GitHub PoC
CVE-2024-10914 Shell Exploit
CVE-2024-10914CRITICAL03 may 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC1
CVE-2016-5195 linux kernel exploit
CVE-2016-5195HIGHbajo ataque02 may 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
katseyres2/CVE-2022-44268-pilgrimage
CVE-2022-44268MEDIUM02 may 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.
CVE-2012-357602 may 2025
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RIESGO
abrir
GitHub PoC
toothbrushsoapflannelbiscuits/cve-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware02 may 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
This python scripts searches a client list to see if their FortiGate device is vulnerable to this CVE.
CVE-2024-23113CRITICALbajo ataque02 may 2025
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
GitHub PoC1
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
CVE-2025-32433CRITICALbajo ataque02 may 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
sattarbug/Analysis-of-TomcatKiller---CVE-2025-31650-Exploit-Tool
CVE-2025-31650HIGH02 may 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir
GitHub PoC1
CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool
CVE-2024-27956CRITICAL01 may 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC
S4mma3l/CVE-2025-24054
CVE-2025-24054MEDIUMbajo ataque01 may 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC9
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
CVE-2025-31324CRITICALbajo ataqueransomware01 may 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC2
CVE-2025-31650 PoC
CVE-2025-31650HIGH30 abr 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir
GitHub PoC2
本脚本是针对 GeoServer 的远程代码执行漏洞(CVE-2024-36401)开发的 PoC(Proof of Concept)探测工具。该漏洞允许攻击者通过构造特定请求,在目标服务器上执行任意命令。
CVE-2024-36401CRITICALbajo ataque30 abr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
GitHub PoC20
A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39)
CVE-2025-31650HIGH30 abr 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir
anteriorpágina 150 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.