Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
75.432 exploits
GitHub PoC1
m2hcz/CVE-2025-6440-Poc-Exploit
CVE-2025-6440CRITICAL29 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
CVE-2018-10933 - LibSSH - Authentication Bypass
CVE-2018-10933CRITICAL29 nov 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
CVE-2025-8088HIGHbajo ataque29 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
KylVGoi/cve-2019-1663
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
GitHub PoC
Exploit - CVE-2023-26360
CVE-2023-26360HIGHbajo ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-2011HIGH28 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
GitHub PoC
AndrewMas99/CVE-2019-11043-Vulnerability
CVE-2019-11043HIGHbajo ataqueransomware28 nov 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
Modified the CVE-2024-25600
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13315CRITICAL28 nov 2025
Unauthenticated log access in Twonky Server
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-26360HIGHbajo ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2010-2075
CVE-2010-207528 nov 2025
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-2198027 nov 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque27 nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque27 nov 2025
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque27 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
CVE-2021-43798 is a high-severity path traversal vulnerability (CVSS 3.1 score: 7.5) affecting Grafana versions 8.0.0-beta1 through 8.3.0. It allows unauthenticated attackers to read arbitrary files from the server by exploiting improper sanitization in the /public/plugins/:pluginId endpoint
CVE-2021-43798HIGHbajo ataque27 nov 2025
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware27 nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.
CVE-2025-55315CRITICAL27 nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RIESGO
abrir
GitHub PoC
Chroot Privilege Escalation
CVE-2025-32463CRITICALbajo ataque27 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHbajo ataqueransomware27 nov 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.
CVE-2023-42793CRITICALbajo ataqueransomware27 nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC4
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
CVE-2025-12735CRITICAL27 nov 2025
CVE-2025-12735
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-58360HIGHbajo ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CVE-2025-32433CRITICALbajo ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC6
XXE through a specific endpoint /geoserver/wms operation GetMap - Geoserver
CVE-2025-58360HIGHbajo ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
CVE-2025-58360
CVE-2025-58360HIGHbajo ataque27 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque27 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems from an improper authentication flaw that allows unauthenticated remote attackers to bypass login mechanisms and gain unauthorized access to sensitive system information
CVE-2017-7921CRITICALbajo ataque27 nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
anteriorpágina 178 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.