Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC5
POC of CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque24 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Quick and easy exploitation of CVE-2024-4956 for LFI.
CVE-2024-4956HIGH24 ago 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3864624 ago 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC114
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALbajo ataque24 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
GitHub PoC
A PHP CGI Vulnerability Scanner for CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware23 ago 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
POC exploit for CVE-2025-33053 (external control of file execution path in URL file)
CVE-2025-33053HIGHbajo ataque23 ago 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Este repositório contém um script de prova de conceito (PoC) que demonstra uma vulnerabilidade crítica encontrada no plugin Simple File List para WordPress.
CVE-2020-36847CRITICAL23 ago 2025
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir
GitHub PoC
donmedfor/CVE-2015-3306
CVE-2015-330623 ago 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC40
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then WebKit(CVE-2025-24201) and Core Media(CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
CVE-2025-24085CRITICALbajo ataque23 ago 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RIESGO
abrir
GitHub PoC
2025年8月20日に公開されたDockerDesktopの脆弱性(対策済み)を実証する
CVE-2025-9074CRITICAL23 ago 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-36847CRITICAL23 ago 2025
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-33053HIGHbajo ataque23 ago 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Sequelize Sql Injection 취약점 구현
CVE-2023-25813CRITICAL23 ago 2025
SQL Injection via replacements in sequelize
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALbajo ataque23 ago 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
GitHub PoC1
Kryptoenix/CVE-2025-47987_PoC
CVE-2025-47987HIGH22 ago 2025
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.
CVE-2016-5195HIGHbajo ataque22 ago 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
0xr2r/CVE-2024-4367
CVE-2024-4367MEDIUM22 ago 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC1
Some poorly crafted exploit scripts
CVE-2025-24893CRITICALbajo ataque22 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque22 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.
CVE-2025-27519CRITICAL22 ago 2025
Cognita Arbitrary File Write
48RIESGO
abrir
GitHub PoC
Telerik CVE-2019-18935 Vulnerability Scanner
CVE-2019-18935CRITICALbajo ataqueransomware22 ago 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
The exploit code for CVE-2025-43300.
CVE-2025-43300CRITICALbajo ataque22 ago 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque22 ago 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1
Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)
CVE-2008-144722 ago 2025
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3721MEDIUM21 ago 2025
TBK DVR-4104/DVR-4216 os command injection
55RIESGO
abrir
GitHub PoC1
CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool
CVE-2023-35078CRITICALbajo ataqueransomware21 ago 2025
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RIESGO
abrir
GitHub PoC
Exploit code for CVE-2015-8351
CVE-2015-835121 ago 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
GitHub PoC
Customized this for my own use
CVE-2023-41892CRITICAL21 ago 2025
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs.
CVE-2025-8088HIGHbajo ataque21 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-835121 ago 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
anteriorpágina 208 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.