Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
75.432 exploits
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque13 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque13 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH13 nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC6
PoC Exploit CVE-2018-6389
CVE-2018-638913 nov 2025
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
keyuraghao/CVE-2025-20260
CVE-2025-20260CRITICAL13 nov 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RIESGO
abrir
GitHub PoC
cyhe50/cve-2025-32434-poc
CVE-2025-32434CRITICAL13 nov 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RIESGO
abrir
GitHub PoC14
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
CVE-2025-7771HIGH13 nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC24
redpack-kr/CVE-2025-60710
CVE-2025-60710HIGHbajo ataque12 nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
local
CVE-2025-60710HIGHbajo ataque12 nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-9802HIGH12 nov 2025
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
41RIESGO
abrir
GitHub PoC
Alex-Acero-Security/CVE-2024-48910-POC
CVE-2024-48910CRITICAL12 nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RIESGO
abrir
GitHub PoC2
Mitchellzhou1/CVE-2024-48910-PoC
CVE-2024-48910CRITICAL11 nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RIESGO
abrir
GitHub PoC
harekrishnarai/CVE-2024-23897-test-windows
CVE-2024-23897CRITICALbajo ataqueransomware11 nov 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC2
CVE-2025-48703 é uma vulnerabilidade de Execução Remota de Código (RCE) no módulo filemanager de um painel de hospedagem web (por exemplo, cPanel). Ocorre devido ao tratamento de entrada não sanitizado na função acc=changePerm, que permite que um atacante injete e execute comandos.
CVE-2025-48703CRITICALbajo ataque11 nov 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
GitHub PoC
CVE-2025-21042
CVE-2025-21042HIGHbajo ataque11 nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
83RIESGO
abrir
GitHub PoC
Vulnerability for Xwiki
CVE-2024-31982CRITICAL11 nov 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RIESGO
abrir
GitHub PoC1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
CVE-2025-11953CRITICALbajo ataque11 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC
Detection for CVE-2025-34299
CVE-2025-34299CRITICAL11 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
CVE-2024-51378CRITICALbajo ataqueransomware11 nov 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-31982CRITICAL11 nov 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RIESGO
abrir
GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
CVE-2025-25257CRITICALbajo ataque11 nov 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-3581311 nov 2025
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque11 nov 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC8
CVE-2025-55315 PoC Exploit
CVE-2025-55315CRITICAL11 nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RIESGO
abrir
VulnCheck XDB
local
CVE-2025-60710HIGHbajo ataque11 nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51378CRITICALbajo ataqueransomware11 nov 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
GitHub PoC2
AstrBot老版本RCE
CVE-2025-55449HIGH11 nov 2025
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us
41RIESGO
abrir
GitHub PoC2
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
CVE-2025-41244HIGHbajo ataque11 nov 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RIESGO
abrir
GitHub PoC5
Wh04m1001/CVE-2025-60710
CVE-2025-60710HIGHbajo ataque11 nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RIESGO
abrir
anteriorpágina 184 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.