Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
13.618 exploits
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 ene 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHbajo ataque30 ene 2025
Openfire administration console authentication bypass
100RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware30 ene 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALbajo ataqueransomware30 ene 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC4
honeyb33z/cve-2020-11023-scanner
CVE-2020-11023MEDIUMbajo ataque30 ene 2025
Potential XSS vulnerability in jQuery
85RIESGO
abrir
GitHub PoC
lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
CVE-2021-2301730 ene 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 ene 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir
GitHub PoC1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware29 ene 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALbajo ataqueransomware29 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
GitHub PoC2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALbajo ataqueransomware28 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
CVE-2024-48248HIGHbajo ataque28 ene 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir
GitHub PoC289
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
CVE-2018-011427 ene 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC77
watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware27 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC1
7-Zip Mark-of-the-Web绕过漏洞PoC(CVE-2025-0411)
CVE-2025-0411HIGHbajo ataque27 ene 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
GitHub PoC
A rewrite of the Polkit vulnerability.
CVE-2021-4034HIGHbajo ataque27 ene 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
CVE-2021-43798 working exploit
CVE-2021-43798HIGHbajo ataque26 ene 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC1
CVE-2016-2555 Exploit
CVE-2016-255526 ene 2025
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
GitHub PoC
Repository for internship test task.
CVE-2024-25600CRITICAL26 ene 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC4
Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.
CVE-2024-9047CRITICAL25 ene 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RIESGO
abrir
GitHub PoC1
Exploit for CVE-2023-4220
CVE-2023-4220HIGH24 ene 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC1
CVE-2024-3673 Exploit: Local File Inclusion in Web Directory Free WordPress Plugin ( before 1.7.3 )
CVE-2024-3673CRITICAL24 ene 2025
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RIESGO
abrir
GitHub PoC8
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2024-55591CRITICALbajo ataqueransomware24 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC
CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.
CVE-2017-7921CRITICALbajo ataque24 ene 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC1
Proof of Concept for CVE-2024-45337 against Gitea and Forgejo
CVE-2024-45337CRITICAL24 ene 2025
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir
GitHub PoC
This repository contains informaion about the Fortigate firewall vulnerability (CVE-2022-40684) and affected data that were publicly disclosed by the Belsen Group. This information is being shared for security research and defensive purposes to help organizations identify if they were impacted.
CVE-2022-40684CRITICALbajo ataqueransomware24 ene 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC1
Course Booking System <= 6.0.5 - Unauthenticated SQL Injection
CVE-2025-22785CRITICAL23 ene 2025
WordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
63RIESGO
abrir
GitHub PoC1
XalfiE/Fortigate-Belsen-Leak-Dump-CVE-2022-40684-
CVE-2022-40684CRITICALbajo ataqueransomware23 ene 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC2
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is especially effective when the /uploads directory is either unprotected or missing on the target server.
CVE-2024-50379CRITICAL23 ene 2025
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC
CVE-2024-38077-POC
CVE-2024-38077CRITICAL23 ene 2025
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RIESGO
abrir
anteriorpágina 180 / 454siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.