Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
75.432 exploits
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL26 nov 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC2
ExtremeUday/CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-
CVE-2025-2945CRITICAL26 nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
CVE-2025-10230CRITICAL26 nov 2025
Samba: command injection in wins server hook script
60RIESGO
abrir
GitHub PoC
CVE-2025-6389
CVE-2025-6389CRITICAL26 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RIESGO
abrir
GitHub PoC3
PoC RCE exploit for Nostromo nhttpd ≤ 1.9.6
CVE-2019-16278CRITICALbajo ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
yunus-a1i/veeam-cve-2023-27532-mock
CVE-2023-27532HIGHbajo ataqueransomware26 nov 2025
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RIESGO
abrir
GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
CVE-2021-41773HIGHbajo ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-58360HIGHbajo ataque26 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-15949HIGHbajo ataque26 nov 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6389CRITICAL25 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-6554HIGHbajo ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
CVE-2024-29943CRITICAL25 nov 2025
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RIESGO
abrir
GitHub PoC31
aklnjakln/CVE-2025-6554
CVE-2025-6554HIGHbajo ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataque25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
CVE-2022-37969HIGHbajo ataque25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
CVE-2025-62168CRITICAL25 nov 2025
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RIESGO
abrir
GitHub PoC
CVE-2025-61757
CVE-2025-61757CRITICALbajo ataque25 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir
Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
CVE-2025-58360HIGHbajo ataque25 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
CVE-2012-212224 nov 2025
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
VulnCheck XDB
local
CVE-2025-11001HIGH24 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
GitHub PoC
CVE-2025-41115
CVE-2025-41115CRITICAL24 nov 2025
Incorrect privilege assignment
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALbajo ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-845124 nov 2025
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
CVE-2023-36845CRITICALbajo ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
CVE-2025-12762
CVE-2025-12762CRITICAL24 nov 2025
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RIESGO
abrir
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir
GitHub PoC
IS8123/CVE-2025-54381
CVE-2025-54381CRITICAL24 nov 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir
GitHub PoC1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
CVE-2025-10230CRITICAL23 nov 2025
Samba: command injection in wins server hook script
60RIESGO
abrir
anteriorpágina 179 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.