Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
CVE-2021-41773HIGHbajo ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
CVE-2025-2776CRITICALbajo ataque31 ago 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir
GitHub PoC2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALbajo ataque31 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir
GitHub PoC1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RIESGO
abrir
GitHub PoC20
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALbajo ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Detection for CVE-2025-4427 and CVE-2025-4428
CVE-2025-4427MEDIUMbajo ataque31 ago 2025
Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque30 ago 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware30 ago 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC4
PHPUnit CVE-2017-9841 Scanner in Go clean and fire.
CVE-2017-9841CRITICALbajo ataque30 ago 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALbajo ataque30 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
tranphuc2005/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware30 ago 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
Aaqilyousuf/CVE-2025-7775-vulnerable-lab
CVE-2025-7775CRITICALbajo ataque30 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir
GitHub PoC5
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
CVE-2025-24201CRITICALbajo ataque30 ago 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RIESGO
abrir
GitHub PoC6
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
CVE-2025-57819CRITICALbajo ataque30 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC2
致远OA存在文件上传导致RCE(CVE-2025-34040)
CVE-2025-34040CRITICAL29 ago 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir
GitHub PoC
CrushFTP AS2 Authentication Bypass
CVE-2025-54309CRITICALbajo ataque29 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque29 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC
Python Script for CVE-2025-49113. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2025-49113CRITICALbajo ataque29 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
arun1033/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque29 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-34040CRITICAL29 ago 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque29 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque29 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC1
soltanali0/CVE-2024-12877-Exploit
CVE-2024-12877CRITICAL28 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL28 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque28 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Naved124/CVE-2024-28397-js2py-Sandbox-Escape
CVE-2024-28397MEDIUM28 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
PoC | NextJS Middleware 15.2.2 - Authorization Bypass
CVE-2025-29927CRITICAL28 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-12877CRITICAL28 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir
anteriorpágina 205 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.