Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.026exploits catalogados
32.224CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.025GitHub PoC 13.340VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
72.030 exploits
GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
Samba: command injection in wins server hook script
60RIESGO
abrir ↗GitHub PoC
yunus-a1i/veeam-cve-2023-27532-mock
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir ↗GitHub PoC★ 2
ExtremeUday/CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
CVE-2025-6389
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗GitHub PoC★ 3
PoC RCE exploit for Nostromo nhttpd ≤ 1.9.6
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir ↗VulnCheck XDB
initial-access
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RIESGO
abrir ↗Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir ↗GitHub PoC★ 31
aklnjakln/CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir ↗GitHub PoC
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir ↗GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RIESGO
abrir ↗GitHub PoC★ 2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC★ 2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗VulnCheck XDB
local
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir ↗VulnCheck XDB
infoleak
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir ↗GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir ↗GitHub PoC
IS8123/CVE-2025-54381
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir ↗GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir ↗GitHub PoC
CVE-2025-12762
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RIESGO
abrir ↗GitHub PoC★ 1
A easy poc for CVE-2024-12084.
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
Samba: command injection in wins server hook script
60RIESGO
abrir ↗GitHub PoC
CVE-2025-11833 Checker
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RIESGO
abrir ↗GitHub PoC★ 2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗GitHub PoC
rashedhasan090/CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.