Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
75.432 exploits
GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
CVE-2024-46256CRITICAL29 oct 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RIESGO
abrir
VulnCheck XDB
local
CVE-2021-31955MEDIUMbajo ataque29 oct 2025
Windows Kernel Information Disclosure Vulnerability
85RIESGO
abrir
GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
CVE-2021-44228CRITICALbajo ataqueransomware28 oct 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL28 oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware28 oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-26360HIGHbajo ataque28 oct 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
CVE-2025-62368CRITICAL28 oct 2025
Taiga Authenticated Remote Code Execution
43RIESGO
abrir
GitHub PoC
A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code execution capabilities on vulnerable Apache 2.4.49 and 2.4.50 servers.
CVE-2021-42013CRITICALbajo ataqueransomware28 oct 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
Exploit for Remote Code Execution in ColdFusion 2021 (CVE-2023-26360)
CVE-2023-26360HIGHbajo ataque28 oct 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
GitHub PoC
ict519 assignment
CVE-2023-38831HIGHbajo ataqueransomware28 oct 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware28 oct 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC97
POC of CVE-2018-9995 written in Rust.
CVE-2018-999528 oct 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
Zohaibkhan1472/cve-2023-6019
CVE-2023-6019CRITICAL28 oct 2025
Ray Command Injection in cpu_profile Parameter
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque28 oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999528 oct 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC1
A Metasploit module for CVE-2024-35374
CVE-2024-35374CRITICAL28 oct 2025
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware28 oct 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Alex-Acero-Security/CVE-2025-20260-POC
CVE-2025-20260CRITICAL27 oct 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque27 oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque27 oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-61882CRITICALbajo ataqueransomware27 oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-29824HIGHbajo ataqueransomware27 oct 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
CaelumIsMe/CVE-2020-29607-POC
CVE-2020-2960727 oct 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir
GitHub PoC
CVE-2021-22204 exiftool rce
CVE-2021-22204MEDIUMbajo ataque27 oct 2025
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22204MEDIUMbajo ataque27 oct 2025
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
Exploit Code for CVE-2018-15473
CVE-2018-15473MEDIUM26 oct 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware26 oct 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque26 oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
aadi0258/Exploit-CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware26 oct 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC7
mcp-remote exposed to OS command injection
CVE-2025-6514CRITICAL26 oct 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RIESGO
abrir
anteriorpágina 188 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.