Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque05 ago 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware04 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque04 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Kai-One001/WordPress-HT-Contact-CVE-2025-7340-RCE
CVE-2025-7340CRITICAL04 ago 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-7340CRITICAL04 ago 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware04 ago 2025
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
CVE-2026-32985CRITICAL04 ago 2025
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RIESGO
abrir
GitHub PoC
A simple Log4j PoC written in Go
CVE-2021-44228CRITICALbajo ataqueransomware04 ago 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
CVE-2025-7441CRITICAL04 ago 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC1
beishanxueyuan/CVE-2025-48384-test
CVE-2025-48384HIGHbajo ataque04 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
CVE-2013-3900 WinVerifyTrust Signature
CVE-2013-3900MEDIUMbajo ataque04 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
CVE-2020-0688HIGHbajo ataqueransomware04 ago 2025
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALbajo ataqueransomware04 ago 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose
CVE-2018-7600CRITICALbajo ataqueransomware04 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC22
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC17
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro.
CVE-2025-24893CRITICALbajo ataque04 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Exploit-DB
Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)
CVE-2025-54589MEDIUMwebappsmultiple03 ago 2025
copyparty Reflected XSS via Filter Parameter
48RIESGO
abrir
Exploit-DB
LPAR2RRD 8.04 - Remote Code Execution (RCE)
CVE-2025-54769HIGHwebappsmultiple03 ago 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir
GitHub PoC
A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.
CVE-2012-298203 ago 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC
Reverse Shell Payload for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC6
PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It allows arbitrary command execution through injection into RSS-based SolrSearch endpoints.
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Exploit-DB
Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation
CVE-2023-3460webappsmultiple03 ago 2025
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
Exploit-DB
Gandia Integra Total 4.4.2236.1 - SQL Injection
CVE-2025-41373HIGHwebappsmultiple03 ago 2025
SQL injection vulnerability in Gandia Integra Total
41RIESGO
abrir
GitHub PoC2
Exploit SQL injection in projectworlds Online Admissions System v1.0
CVE-2025-8471MEDIUM03 ago 2025
projectworlds Online Admission System adminlogin.php sql injection
33RIESGO
abrir
Exploit-DB
Swagger UI 1.0.3 - Cross-Site Scripting (XSS)
CVE-2025-8191MEDIUMremotemultiple03 ago 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir
GitHub PoC
This is a small script for the rce vulnerability for CVE-2025-24893. It supports basic input/output
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
dhiaZnaidi/CVE-2025-24893-PoC
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC5
Modified exploit for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
anteriorpágina 218 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.