Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
VulnCheck XDB
local
CVE-2025-48384HIGHbajo ataque01 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque01 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALbajo ataque01 ago 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
GitHub PoC
CVE-2025-48703 là lỗ hổng mức độ nghiêm trọng trong CentOS Web Panel (CWP) cho phép kẻ tấn công không xác thực (unauthenticated) có thể thực thi mã từ xa (RCE) thông qua bỏ qua cơ chế xác thực và thực thi câu lệnh hệ thống. Lỗ hổng ảnh hưởng CWP từ phiên bản 0.9.8.1204 trở về trước, và đã được vá trên phiên bản mới nhất 0.9.8.1205.
CVE-2025-48703CRITICALbajo ataque01 ago 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
GitHub PoC
test for CVE-2025-48384
CVE-2025-48384HIGHbajo ataque01 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC2
PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1
CVE-2025-41373HIGH01 ago 2025
SQL injection vulnerability in Gandia Integra Total
41RIESGO
abrir
GitHub PoC
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class.
CVE-2017-1262901 ago 2025
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RIESGO
abrir
GitHub PoC2
Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage threats, and rooted device attacks. Educational PoCs with working code, exploitation scripts, and security controls for developers and researchers. To be updated...
CVE-2017-1315601 ago 2025
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC
Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying malicious payload patterns using a custom firewall_server.py and tests them with test_requests.py.
CVE-2022-22965CRITICALbajo ataque01 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
This Python exploit targets a critical unauthenticated Remote Code Execution (RCE) vulnerability in the BigUp plugin of SPIP CMS (≤ 4.3.1, 4.2.15, 4.1.17). It abuses the bigup_retrouver_fichiers parameter, allowing attackers to execute arbitrary PHP via upload progress features, without authentication.
CVE-2024-8517CRITICAL01 ago 2025
SPIP Bigup Multipart File Upload OS Command Injection
85RIESGO
abrir
GitHub PoC
Spring4Shell (POC)
CVE-2022-22965CRITICALbajo ataque01 ago 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC4
CVE‑2025‑5394 WP Alone ≤ 7.8.3
CVE-2025-5394CRITICAL31 jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir
GitHub PoC
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samba RPC, to do this you need to have account with access to the samba.
CVE-2025-33073HIGHbajo ataque31 jul 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC
KiPhuong/challenge-cve-2024-3552
CVE-2024-3552CRITICAL31 jul 2025
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RIESGO
abrir
GitHub PoC90
CVE-2025-30406 ViewState Exploit PoC
CVE-2025-30406CRITICALbajo ataque31 jul 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALbajo ataque31 jul 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
GitHub PoC2
PoC for CVE-2025-54589 – a reflected XSS vulnerability in Copyparty ≤ 1.18.6.
CVE-2025-54589MEDIUM31 jul 2025
copyparty Reflected XSS via Filter Parameter
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-51482HIGH31 jul 2025
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMbajo ataque31 jul 2025
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
mouftan/CVE-2022-44268
CVE-2022-44268MEDIUM31 jul 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
Educational PoC for Dirty COW (CVE-2016-5195) with logging, ptrace fallback, and binary payload support.
CVE-2016-5195HIGHbajo ataque31 jul 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
maxntv/CVE-2023-22894-PoC
CVE-2023-22894CRITICAL31 jul 2025
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL31 jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir
GitHub PoC21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29824HIGHbajo ataqueransomware30 jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque30 jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
CVE-2017-5638CRITICALbajo ataqueransomware30 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
rgvillanueva28/vulnbox-easy-CVE-2025-29927
CVE-2025-29927CRITICAL30 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALbajo ataqueransomware30 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir
GitHub PoC1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
CVE-2025-14847HIGHbajo ataque30 jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
anteriorpágina 220 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.