Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC10
CVE-2025-30208-EXP 任意文件读取
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC250
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
CVE-2025-1097HIGH26 mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RIESGO
abrir
GitHub PoC
CVE-2025-30208 任意文件读取漏洞快速验证
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC198
CVE-2025-30208-EXP
CVE-2025-30208MEDIUM26 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC4
PoC of CVE-2025-1974, modified from the world-first PoC~
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC7
Poc for Ingress RCE
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
CVE-2025-1974CRITICAL26 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
CVE-2025-22912
CVE-2025-22912CRITICAL25 mar 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RIESGO
abrir
GitHub PoC
yanmarques/CVE-2025-1974
CVE-2025-1974CRITICAL25 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC53
yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL25 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.
CVE-2018-15473MEDIUM25 mar 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
CVE-2025-29972CRITICAL25 mar 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RIESGO
abrir
GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
0xPb1/Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
jeymo092/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
0xPThree/next.js_cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
0xcucumbersalad/cve-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
CVE-2025-29927CRITICAL25 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
somatrasss/CVE-2025-29306
CVE-2025-29306CRITICAL25 mar 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
CVE-2024-31114CRITICAL25 mar 2025
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
POC for CVE-2023-30258-RCE by n0o0b
CVE-2023-30258CRITICAL25 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
CVE-2024-21413CRITICALbajo ataque25 mar 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHbajo ataque25 mar 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
anteriorpágina 162 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.