Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC44
This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.
CVE-2019-2215HIGHbajo ataque13 mar 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2015-0009 (SMB Signing)
CVE-2015-000912 mar 2025
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RIESGO
abrir
GitHub PoC7
tinashelorenzi/CVE-2023-30258-magnus-billing-v7-exploit
CVE-2023-30258CRITICAL12 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware12 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
MS17-010 (CVE-2017-0143) - Python3 Script
CVE-2017-0143HIGHbajo ataqueransomware12 mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC1
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
CVE-2025-28915CRITICAL12 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
POC for CVE-2025-26240
CVE-2025-26240HIGH12 mar 2025
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t
41RIESGO
abrir
GitHub PoC
CVE-2024-8289 https://www.cve.org/CVERecord?id=CVE-2024-8289, Vendor wcmp Product MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution
CVE-2024-8289CRITICAL11 mar 2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover
48RIESGO
abrir
GitHub PoC
CVE-2024-54383, https://www.cve.org/CVERecord?id=CVE-2024-54383
CVE-2024-54383CRITICAL11 mar 2025
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2024-10924 - Authentication Bypass in ReallySimpleSSL Wordpress Plugin
CVE-2024-10924CRITICAL11 mar 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
CVE-2017-11882 Preventer for .docx files
CVE-2017-11882HIGHbajo ataqueransomware11 mar 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
KQL para deteccion de CVE-2025-21333 en Sentinel
CVE-2025-21333HIGHbajo ataque11 mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and CVE-2021-42013, which involve Path Traversal and Remote Code Execution (RCE).
CVE-2021-41773HIGHbajo ataqueransomware11 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Remote code execution running on w3 total cache cve 2013-2010
CVE-2013-201011 mar 2025
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC15
Exploit for CVE-2024-0402 in Gitlab
CVE-2024-0402CRITICAL10 mar 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
48RIESGO
abrir
GitHub PoC
Sp4ceDogy/NPE-CS-V-CVE-2021-1675
CVE-2021-1675HIGHbajo ataqueransomware10 mar 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
Ivanti Remote code execution
CVE-2025-0282CRITICALbajo ataqueransomware10 mar 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-
CVE-2021-3156HIGHbajo ataque10 mar 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC4
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.
CVE-2023-27350CRITICALbajo ataqueransomware09 mar 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC
sk00l/CVE-2023-30258
CVE-2023-30258CRITICAL09 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC
progress moveit cve-2024-5806
CVE-2024-5806CRITICAL08 mar 2025
MOVEit Transfer Authentication Bypass Vulnerability
85RIESGO
abrir
GitHub PoC
cve-2017-5487 wp rest api 취약점
CVE-2017-548708 mar 2025
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC
elphon/CVE-2007-2447-Exploit
CVE-2007-244708 mar 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
Zimbra CVE-2024-45519
CVE-2024-45519CRITICALbajo ataque08 mar 2025
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
GitHub PoC1
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). This is a memory corruption PoC
CVE-2025-21298CRITICAL07 mar 2025
Windows OLE Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
CVE-2023-40028 is a security vulnerability affecting Ghost CMS versions prior to 5.59.1.
CVE-2023-40028MEDIUM07 mar 2025
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC
Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.
CVE-2020-1472MEDIUMbajo ataqueransomware07 mar 2025
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC4
Python3 Rewrite of SmarterMail < Build 6985 Remote Code Execution found by 1F98D (CVE-2019-7214) POC
CVE-2019-721407 mar 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
GitHub PoC2
Arbitrary file read in Grafana allows an attacker to read server files by abusing a path traversal.
CVE-2021-43798HIGHbajo ataque06 mar 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
CVE-2024-32002CRITICAL06 mar 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
anteriorpágina 166 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.