Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC4
POC exploit for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
A POC for CVE-2025-24893 written in python
CVE-2025-24893CRITICALbajo ataque09 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC6
POC for CVE-2025-4404
CVE-2025-4404CRITICAL09 ago 2025
Freeipa: idm: privilege escalation from host to domain admin in freeipa
48RIESGO
abrir
GitHub PoC
一个由AI生成的漏洞验证应用
CVE-2022-22947CRITICALbajo ataque08 ago 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque08 ago 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-24354MEDIUM08 ago 2025
imgproxy is vulnerable to SSRF against 0.0.0.0
48RIESGO
abrir
GitHub PoC
This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.
CVE-2018-7600CRITICALbajo ataqueransomware08 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC6
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
POC
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC26
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
CVE-2025-32463CRITICALbajo ataque08 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque08 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.
CVE-2025-8730CRITICAL08 ago 2025
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RIESGO
abrir
GitHub PoC1
PoC to inject a command via the DEVICE_PING endpoint
CVE-2025-7769HIGH07 ago 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RIESGO
abrir
GitHub PoC
Scouserr/cve-2022-0847-poc-dockerimage
CVE-2022-0847HIGHbajo ataque07 ago 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC5
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL07 ago 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
Bash POC script for RCE vulnerability in XWiki Platform
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30406CRITICALbajo ataque07 ago 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC1
CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC1
Th3Gl0w/CVE-2025-24893-POC
CVE-2025-24893CRITICALbajo ataque07 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
CVE-2025-34152CRITICAL07 ago 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
CVE-2025-50286HIGH07 ago 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir
GitHub PoC4
soltanali0/CVE-2025-5777-Exploit
CVE-2025-5777CRITICALbajo ataqueransomware07 ago 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
anteriorpágina 216 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.