Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC7
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantiate arbitrary record types during parsing, enabling code execution when untrusted data is processed without proper controls.
CVE-2025-30065CRITICAL04 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
sn1p3rt3s7/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
PoC for CVE-2024-25600
CVE-2024-25600CRITICAL04 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
CVE-2024-53900CRITICAL03 abr 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir
GitHub PoC7
CVE-2025-30208 - Vite Arbitrary File Read PoC
CVE-2025-30208MEDIUM03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
CVE-2025-29927CRITICAL03 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
h4ckxel/CVE-2025-2005
CVE-2025-2005CRITICAL03 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
CVE-2025-2594HIGH02 abr 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RIESGO
abrir
GitHub PoC
Next.js and the corrupt middleware...TRY TO HACK IT..!
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
CVE-2025-2005CRITICAL02 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
GitHub PoC
corsisechero/CVE-2019-9193byVulHub
CVE-2019-919302 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A demo exploit for CVE-2021-44026, a SQL injection in Roundcube
CVE-2021-44026CRITICALbajo ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC
0xshaheen/CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
mass scan for CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC2
Detection of malicious VHD files for CVE-2025-24985
CVE-2025-24985HIGHbajo ataque02 abr 2025
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
71RIESGO
abrir
GitHub PoC
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
CVE-2023-29357CRITICALbajo ataqueransomware01 abr 2025
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass ACLs by desynchronizing request parsing between ICM and backend services using crafted Content-Length-based payloads.
CVE-2022-22536CRITICALbajo ataque01 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
GitHub PoC
Next.js CVE-2025-29927 güvenlik açığı hakkında
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
Next.js Middleware Bypass Vulnerability
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC6
Vite 任意文件读取漏洞POC
CVE-2025-31125MEDIUMbajo ataque01 abr 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
GitHub PoC
JOOJIII/CVE-2025-29927
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
congdong007/CVE-2024-50623-poc
CVE-2024-50623CRITICALbajo ataqueransomware01 abr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
GitHub PoC
Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.
CVE-2019-905331 mar 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC5
Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability
CVE-2023-21554CRITICAL31 mar 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC
backdoor.mirai.helloworld cve2018-20561, cve-2018-10562 해킹
CVE-2018-10562CRITICALbajo ataqueransomware31 mar 2025
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC
mrrivaldo/CVE-2025-2294
CVE-2025-2294CRITICAL31 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
B1gN0Se/Tomcat-CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque31 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC7
针对CVE-2025-30208和CVE-2025-31125的漏洞利用
CVE-2025-30208MEDIUM31 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
anteriorpágina 159 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.