Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9029Nuclei 4416Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
GitHub PoC
A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with interactive shell access, command logging, and automated PDF/DOCX reporting.
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir ↗GitHub PoC
Laboratorio para el análisis y explotación del CVE-2025-5548
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗GitHub PoC
Proof-of-concept (PoC) for CVE-2021-41773, demonstrating Apache HTTP Server 2.4.49 path traversal and remote code execution (RCE) in a controlled lab environment.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC
Research and exploitation lab for CVE-2025-5548: Stack Buffer Overflow in FreeFloat FTP Server. Static analysis (IDA/Ghidra), fuzzing, payload engineering and reverse shell.
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗VulnCheck XDB
info-leak
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 30
CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8)
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir ↗GitHub PoC
Red Team exploitation of CVE-2021-3156 (Baron Samedit) – Heap Buffer Overflow in Sudo leading to Local Privilege Escalation on Ubuntu 20.04
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
jesusdominguez87/CVE-2025-5548
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
Apache 2.4.49 Path Traversal RCE
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
Documentación paso a paso del análisis y la explotación controlada de la CVE-2025-5548 en FreeFloat FTP Server 1.0, incluyendo preparación del entorno, análisis técnico, desarrollo del exploit y validación final.
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗VulnCheck XDB
denial-of-service
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC
Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of unauthenticated SQL Injection and its consequences for global data privacy, affecting 2,700+ organizations. Special thanks to Professor David J. Malan and the CS50 staff.
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗GitHub PoC
Buffer overflow in FreeFloat FTP Server 1.0
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗GitHub PoC
REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized environments. It sends crafted POST requests to targets, analyzes server responses for execution indicators, and supports batch scanning with custom input, structured payload handling, and clear CLI output.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
a PoC for the Nagios CVE-2019-15949 rce in python
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir ↗GitHub PoC
CVE-2021-44228 Log4Shell — Penetration Test Writeup
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash replication, and environment setup for vulnerability research.
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗Metasploit600
Gogs Git Rebase Argument Injection RCE
Gogs: RCE via git rebase --exec argument injection in pull request merge
63RIESGO
abrir ↗GitHub PoC★ 1
uname1able/CVE-2025-29824
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC
12-test-12/CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.