Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC
Built to call on CVE-2025-48384-PoC-Part2 for RCE
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
RCE hook
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
jacobholtz/CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
PoC for CVE-2025-48384
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC11
IOS audio buffer overflow CVE-2025-31200 POC
CVE-2025-31200CRITICALbajo ataque28 ago 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Mdusmandasthaheer/CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque28 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
Detection for CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque28 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.
CVE-2007-244727 ago 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC8
A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC10
Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque27 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
te0rwx/CVE-2025-32433-Detection
CVE-2025-32433CRITICALbajo ataque27 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC5
walidpyh/CVE-2025-8088
CVE-2025-8088HIGHbajo ataque27 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque27 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework integration
CVE-2018-19323CRITICALbajo ataqueransomware27 ago 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RIESGO
abrir
VulnCheck XDB
local
CVE-2018-19323CRITICALbajo ataqueransomware27 ago 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RIESGO
abrir
GitHub PoC
hacieda/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque27 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC5
yukinime/CVE-2025-6934
CVE-2025-6934CRITICAL27 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC3
用于CVE-2025-32463 sudo_chwoot的权限提升POC,适配了有gcc编译环境和无gcc编译环境的两种情况,下载运行即可一把梭哈
CVE-2025-32463CRITICALbajo ataque27 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
Exploit-DB
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
CVE-2025-4427MEDIUMbajo ataqueremotemultiple26 ago 2025
Authentication Bypass
100RIESGO
abrir
GitHub PoC
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVE-2025-34030CRITICAL26 ago 2025
sar2html OS Command Injection
75RIESGO
abrir
VulnCheck XDB
local
CVE-2019-6693MEDIUMbajo ataqueransomware26 ago 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RIESGO
abrir
Exploit-DB
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
CVE-2025-7441CRITICALwebappsmultiple26 ago 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
CVE-2025-26263MEDIUMlocalwindows26 ago 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RIESGO
abrir
GitHub PoC1
DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
CVE-2025-8088HIGHbajo ataque26 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
anteriorpágina 206 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.