Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
75.432 exploits
GitHub PoC5
demo CVE-2019-2215 (Bad Binder) for Android Q
CVE-2019-2215HIGHbajo ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque06 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque06 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-64095CRITICAL06 nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54782CRITICAL06 nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque06 nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALbajo ataque06 nov 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALbajo ataque05 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14883HIGHbajo ataque05 nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware05 nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
CVE-2023-30258CRITICAL05 nov 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC8
CVE-2025-53690 POC
CVE-2025-53690CRITICALbajo ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53690CRITICALbajo ataque05 nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
CVE-2024-4040CRITICALbajo ataque05 nov 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
CVE-2025-11953CRITICALbajo ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC
PoC for CVE-2024-5932.
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVE-2025-11749CRITICAL04 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RIESGO
abrir
GitHub PoC10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
CVE-2025-54253CRITICALbajo ataque04 nov 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque04 nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALbajo ataque04 nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL04 nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
GitHub PoC8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
CVE-2025-63353CRITICAL04 nov 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque03 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque03 nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
XWiki Unauthenticated RCE Exploit for Reverse Shell
CVE-2025-24893CRITICALbajo ataque03 nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2011HIGH02 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
GitHub PoC1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
CVE-2015-330602 nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC1
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974CRITICAL02 nov 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
anteriorpágina 186 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.