Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.526 exploits
GitHub PoC
Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir ↗GitHub PoC★ 2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir ↗GitHub PoC★ 21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗GitHub PoC
Technical Details and Exploit for CVE-2025-50460
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i
48RIESGO
abrir ↗GitHub PoC★ 1
Technical Details and Exploit for CVE-2025-50472
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste
48RIESGO
abrir ↗VulnCheck XDB
client-side
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
76RIESGO
abrir ↗GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir ↗GitHub PoC★ 1
DLL00P/CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗GitHub PoC★ 4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Exploit-DB
XWiki 14 - SQL Injection via getdeleteddocuments.vm
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗GitHub PoC
imbas007/CVE-2025-32429-Checker
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗GitHub PoC
r0otk3r/CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗Exploit-DB
Adobe ColdFusion 2023.6 - Remote File Read
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗Exploit-DB
Linux PAM Environment - Variable Injection Local Privilege Escalation
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗Exploit-DB
Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RIESGO
abrir ↗VulnCheck XDB
client-side
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC★ 2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir ↗GitHub PoC★ 5
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 2
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir ↗GitHub PoC
r3xbugbounty/CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.