Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
CVE-2025-34028CRITICALbajo ataque24 abr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
CVE-2018-1574524 abr 2025
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
GitHub PoC3
CVE-2023-25157 exp
CVE-2023-25157CRITICAL24 abr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
GitHub PoC12
Exploit for CVE-2025-30406
CVE-2025-30406CRITICALbajo ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
GitHub PoC
JIYUN02/cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware24 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Optimized exploit for CVE-2021-43857 affecting Gerapy < 0.9.8
CVE-2021-43857CRITICAL24 abr 2025
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir
GitHub PoC12
F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL23 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.
CVE-2024-49138HIGHbajo ataque23 abr 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC2
CVE-2025-29927: Next.js Middleware Bypass Vulnerability
CVE-2025-29927CRITICAL23 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
Tool designed to scan a list of websites for a known vulnerability in the PHPUnit framework, specifically the CVE-2017-9841 vulnerability.
CVE-2017-9841CRITICALbajo ataque22 abr 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC1
inok009/FOXCMS-CVE-2025-29306-POC
CVE-2025-29306CRITICAL22 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC1
Demo for detection and mitigation of HTTP/2 Rapid Reset vulnerability (CVE-2023-44487)
CVE-2023-44487HIGHbajo ataque22 abr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC20
Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071
CVE-2025-24054MEDIUMbajo ataque22 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
custiya/geoserver-CVE-2023-25157
CVE-2023-25157CRITICAL21 abr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir
GitHub PoC1
A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked as CVE-2025-30065, this flaw affects Apache Parquet ≤ 1.15.0. All users must upgrade to version 1.15.1 immediately to mitigate exploitation risks.
CVE-2025-30065CRITICAL21 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC118
CVE-2025-31200 - @Noahhw46 figured it out
CVE-2025-31200CRITICALbajo ataque21 abr 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
GitHub PoC2
A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects Wazuh versions ≥ 4.4.0 and has been patched in version 4.9.1.
CVE-2025-24016CRITICALbajo ataque21 abr 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC1
CVE-2025-30208 vite file read nuclei template
CVE-2025-30208MEDIUM21 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALbajo ataque21 abr 2025
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC
pswalia2u/CVE-2025-24071_POC
CVE-2025-24071MEDIUM21 abr 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC2
pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-
CVE-2025-29927CRITICAL21 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
CrushFTP CVE-2025-31161 Exploit Tool 🔓
CVE-2025-31161CRITICALbajo ataqueransomware21 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2020-0796CRITICALbajo ataqueransomware20 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2019-7238CRITICALbajo ataque20 abr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
GitHub PoC2
mouseos/cve-2019-2215_SH-M08
CVE-2019-2215HIGHbajo ataque20 abr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2023-43770MEDIUMbajo ataque20 abr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2021-44026CRITICALbajo ataque20 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2020-35730MEDIUMbajo ataque20 abr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RIESGO
abrir
GitHub PoC1
cybermads/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC2
Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.
CVE-2022-0847HIGHbajo ataque19 abr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
anteriorpágina 153 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.