Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC
A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)
CVE-2018-7600CRITICALbajo ataqueransomware21 sep 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
A working (at least for me :] ) exploit for CVE-2025-25257
CVE-2025-25257CRITICALbajo ataque21 sep 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC1
iteride/CVE-2025-29927
CVE-2025-29927CRITICAL21 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC2
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL21 sep 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-34152CRITICAL21 sep 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware21 sep 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2025-10035CRITICALbajo ataqueransomware21 sep 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL21 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CVE-2018-13379 - Fortinet SSL VPN Vulnerability
CVE-2018-13379CRITICALbajo ataqueransomware21 sep 2025
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque21 sep 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque20 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC19
Detection for CVE-2025-10035
CVE-2025-10035CRITICALbajo ataqueransomware20 sep 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL20 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque20 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected software/library here if known]. This tool provides automated scanning, reporting, and optional mitigation steps to help administrators and security teams secure their environments quickly.
CVE-2024-3094CRITICAL20 sep 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC1
This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It intentionally executes commands from crafted input for local learning only.
CVE-2025-20265CRITICAL20 sep 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RIESGO
abrir
GitHub PoC
pucagit/CVE-2025-9074
CVE-2025-9074CRITICAL20 sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC1
🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.
CVE-2025-32463CRITICALbajo ataque20 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
sdrtba/CVE-2025-29927
CVE-2025-29927CRITICAL20 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
CVE-2025-49113 - Roundcube Remote Code Execution
CVE-2025-49113CRITICALbajo ataque19 sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque19 sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC13
Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.
CVE-2025-10585HIGHbajo ataque19 sep 2025
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr
71RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29306CRITICAL18 sep 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC1
A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters via GraphQL mutations, and how to detect, analyze, and report the breach using ELK.
CVE-2025-59359CRITICAL18 sep 2025
OS command injection in Chaos Mesh via the cleanTcs mutation
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL18 sep 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque18 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC
HK4zCzi/CVE-2019-3396-Velocity-Server-Side-Template-Injection
CVE-2019-3396CRITICALbajo ataqueransomware18 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
veniversum/cve-2025-43300
CVE-2025-43300CRITICALbajo ataque18 sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC
WinRAR漏洞CVE-2025-8088的payload一键生成工具
CVE-2025-8088HIGHbajo ataque18 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC2
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.
CVE-2025-57819CRITICALbajo ataque18 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
anteriorpágina 197 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.