Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
75.445 exploits
GitHub PoC★ 2
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains how attackers can escape container boundaries, compromise AI workloads, and how tools like Sentinel can detect and mitigate the threat
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir ↗GitHub PoC
Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗GitHub PoC★ 10
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗GitHub PoC
CTY-Research-1/CVE-2025-47812_Lab_environment
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
56RIESGO
abrir ↗GitHub PoC★ 3
This is CVE-2025-53690 Analysis Documents.
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir ↗GitHub PoC★ 2
FOGProject Authentication bypass CVE-2025-58443 Exploit
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir ↗GitHub PoC
oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗GitHub PoC★ 1
This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗GitHub PoC
This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗GitHub PoC
MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 6
exploit SQL injection ELEX WooCommerce Google Shopping
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RIESGO
abrir ↗GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RIESGO
abrir ↗GitHub PoC
cve-2025-33073/cve-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗GitHub PoC
tranphuc2005/CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗GitHub PoC
whisperer1290/CVE-2025-54309__Enhanced_exploit
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗GitHub PoC★ 2
PoC for CVE-2015-5736
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗GitHub PoC
Python script to execute CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 1
Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
48RIESGO
abrir ↗GitHub PoC
andwati/CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.