Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
CVE-2025-24071MEDIUM18 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL18 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
GitHub PoC5
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC3
Nuclei Template CVE-2025–24813
CVE-2025-24813CRITICALbajo ataque17 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
KillReal01/CVE-2023-4911
CVE-2023-4911HIGHbajo ataque17 mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC1
Jimmy01240397/CVE-2024-12641_12642_12645
CVE-2024-12641CRITICAL17 mar 2025
Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE
48RIESGO
abrir
GitHub PoC1
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
CVE-2024-25641CRITICAL17 mar 2025
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
GitHub PoC1
orilevy8/cve-2023-0386
CVE-2023-0386HIGHbajo ataque17 mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
CVE-2024-9047CRITICAL16 mar 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
CVE-2013-3900MEDIUMbajo ataque16 mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2023-30258CRITICAL16 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
CVE-2019-19781CRITICALbajo ataqueransomware16 mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC403
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
CVE-2025-24071MEDIUM16 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC16
CVE-2025-24813利用工具
CVE-2025-24813CRITICALbajo ataque16 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC45
一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具
CVE-2024-4577CRITICALbajo ataqueransomware15 mar 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
CVE-2024-51788CRITICAL15 mar 2025
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
CVE-2025-22604CRITICAL15 mar 2025
Cacti has Authenticated RCE via multi-line SNMP responses
48RIESGO
abrir
GitHub PoC2
PoC - OpenSSL NPN Buffer Overread
CVE-2024-5535CRITICAL15 mar 2025
SSL_select_next_proto buffer overread
48RIESGO
abrir
GitHub PoC2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
CVE-2016-5195HIGHbajo ataque15 mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298214 mar 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC1
User name enumeration against SSH daemons affected by CVE-2016-6210.
CVE-2016-6210MEDIUM14 mar 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC
DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected
CVE-2024-49138HIGHbajo ataque14 mar 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
redpack-kr/CVE-2025-26319
CVE-2025-26319CRITICAL14 mar 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RIESGO
abrir
GitHub PoC
Pei4AN/CVE-2025-28915
CVE-2025-28915CRITICAL14 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
Security Researcher
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC3
CVE-2025-24813_POC
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC11
cve-2025-24813验证脚本
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC196
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC97
Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)
CVE-2025-24813CRITICALbajo ataque13 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC
CVE-2025-1661CRITICAL13 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
anteriorpágina 165 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.