Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
Project Repository for Exploitation, Detection and Mitigation of Folina Vulnerability (CVE-2022-30190)
CVE-2022-30190HIGHbajo ataqueransomware08 abr 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
CVE-2025-31651 PoC
CVE-2025-31651CRITICAL08 abr 2025
Apache Tomcat: Bypass of rules in Rewrite Valve
48RIESGO
abrir
GitHub PoC1
0xnxt1me/CVE-2025-29927
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL07 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
CVE-2019-5418HIGHbajo ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC
vances25/CVE-2024-44871
CVE-2024-44871HIGH07 abr 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RIESGO
abrir
GitHub PoC
Heimd411/CVE-2025-24813-noPoC
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
DFG register allocation bug in JavaScriptCore
CVE-2024-44308HIGHbajo ataque07 abr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RIESGO
abrir
GitHub PoC3
mouadk/parquet-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL07 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
CVE-2023-23397CRITICALbajo ataque07 abr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC32
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHbajo ataque06 abr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
CVE-2024-10924CRITICAL06 abr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
VVeakee/CVE-2024-4367
CVE-2024-4367MEDIUM06 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC1
cybermads/CVE-2011-2523
CVE-2011-252306 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
Koray123-debug/CVE-2024-34102
CVE-2024-34102CRITICALbajo ataque06 abr 2025
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALbajo ataque06 abr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
GitHub PoC3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
CVE-2025-2005CRITICAL06 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC2
CVE-2025-24813-POC JSP Web Shell Uploader
CVE-2025-24813CRITICALbajo ataque06 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header
CVE-2025-29927CRITICAL05 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.
CVE-2025-24813CRITICALbajo ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC4
simple exp for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque05 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
CVE-2025-30065 PoC
CVE-2025-30065CRITICAL05 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC1
Vite-CVE-2025-30208-EXP单目标检测,支持自定义读取路径,深度检索
CVE-2025-30208MEDIUM05 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
CVE-2011-252305 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC12
PoC
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability
CVE-2021-38163CRITICALbajo ataque04 abr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir
GitHub PoC
WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)
CVE-2025-30911CRITICAL04 abr 2025
WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
48RIESGO
abrir
anteriorpágina 157 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.