Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque05 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
andwati/CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque05 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC1
Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation
CVE-2025-49388CRITICAL05 sep 2025
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
48RIESGO
abrir
GitHub PoC134
FairPlay decryptor (dump iPA) for iOS Application that running on macOS with SIP-enabled, using CVE-2025-24204. Support macOS 15.0-15.2
CVE-2025-24204CRITICAL04 sep 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RIESGO
abrir
GitHub PoC1
cve-2025-23266-migration-bypass
CVE-2025-23266CRITICAL04 sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir
GitHub PoC
neverhavenamee/CVE-2020-7961
CVE-2020-7961CRITICALbajo ataque04 sep 2025
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-5016404 sep 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RIESGO
abrir
GitHub PoC
Real-world patching workflow for CVE-2025-32709. From hotfix install to SIEM alert validation—this repo documents every step with screenshots, commands, and detection logic.
CVE-2025-32709HIGHbajo ataque04 sep 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC4
saladin0x1/CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware04 sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque04 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque04 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware04 sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC5
Detection for CVE-2025-53690
CVE-2025-53690CRITICALbajo ataque04 sep 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-53772HIGH04 sep 2025
Web Deploy Remote Code Execution Vulnerability
46RIESGO
abrir
VulnCheck XDB
local
CVE-2024-1086HIGHbajo ataqueransomware04 sep 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
VulnCheck XDB
local
CVE-2025-1055MEDIUM04 sep 2025
K7 Security Anti-Malware: IOCTL in K7RKScan.sys Allows Arbitrary Termination of High-Privilege and System Processes by a Low-Privilege User
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque04 sep 2025
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC1
FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).
CVE-2025-57819CRITICALbajo ataque04 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC40
A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header manipulation.
CVE-2025-8088HIGHbajo ataque04 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
vulnerability in NGINX servers (versions 0.6.18–1.20.0). The scripts aim to cause a Denial of Service (DoS) by sending malicious DNS responses, with enhancements to bypass firewalls.
CVE-2021-2301704 sep 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
GitHub PoC
Educational, non-functional Linux kernel exploit template for CVE-2024-1086 — lab-only security research and teaching (use in controlled VMs only).
CVE-2024-1086HIGHbajo ataqueransomware04 sep 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC2
Reproducible lab for CVE-2020-0610 (BlueGate) - Windows RD Gateway UDP/DTLS remote code execution vulnerability. Includes PowerShell scripts, setup guide, and nuclei template validation examples.
CVE-2020-061003 sep 2025
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
35RIESGO
abrir
GitHub PoC1
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
CVE-2016-15042CRITICAL03 sep 2025
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
63RIESGO
abrir
GitHub PoC2
Exploitation scripts for the CrushFTP CVE-2025-54309: vulnerability
CVE-2025-54309CRITICALbajo ataque03 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware03 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
CVE-2025-9074CRITICAL03 sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC
This is a PoC for the CVE-2025-24813 and tested in different environments.
CVE-2025-24813CRITICALbajo ataque03 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH03 sep 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
GitHub PoC
CVE-2025-3248
CVE-2025-3248CRITICALbajo ataqueransomware03 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
anteriorpágina 203 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.