Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
CVE-2015-10141CRITICAL17 ago 2025
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALbajo ataque17 ago 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
CVE-2025-8088HIGHbajo ataque17 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
GitHub PoC1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir
GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
CVE-2019-1218517 ago 2025
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RIESGO
abrir
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
CVE-2020-5410HIGHbajo ataque17 ago 2025
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CVE-2011-273217 ago 2025
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-742216 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
CVE-2018-742216 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
CVE-2025-6934CRITICAL16 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
Ash1996x/CVE-2025-50154-Aggressor-Script
CVE-2025-50154MEDIUM16 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
CVE-2011-436716 ago 2025
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RIESGO
abrir
GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
CVE-2023-37908CRITICAL16 ago 2025
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
CVE-2023-37582CRITICAL16 ago 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
CVE-2025-8088HIGHbajo ataque16 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version 1.890 (CVE-2019-15107), ultimately gaining full control over the target system.
CVE-2019-15107CRITICALbajo ataqueransomware16 ago 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
shoucheng3/apache__shiro_CVE-2023-34478_1-11-0
CVE-2023-34478CRITICAL16 ago 2025
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque16 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque16 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25256CRITICAL15 ago 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
75RIESGO
abrir
VulnCheck XDB
local
CVE-2025-8088HIGHbajo ataque15 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
CVE-2025-8088HIGHbajo ataque15 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
hlc23/CVE-2024-5932-web-ui
CVE-2024-5932CRITICAL15 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
GitHub PoC1
0xr2r/CVE-2017-11317-auto-exploit-
CVE-2017-11317CRITICALbajo ataque15 ago 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
GitHub PoC4
Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports single/multi-target scanning, and includes a harmless local PoC marker.
CVE-2025-20265CRITICAL15 ago 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RIESGO
abrir
GitHub PoC22
sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324
CVE-2025-31324CRITICALbajo ataqueransomware15 ago 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALbajo ataqueransomware15 ago 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC4
A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.
CVE-2024-3660CRITICAL15 ago 2025
Arbitrary code injection vulnerability in Keras framework < 2.13
48RIESGO
abrir
anteriorpágina 211 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.