Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
GitHub PoC5
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
CVE-2025-24813CRITICALbajo ataque28 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC2
Exploit for CVE-2022-35411 — Unauthenticated RCE in rpc.py (<= 0.6.0)
CVE-2022-3541128 jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
Exploit-DB
Linux PAM Environment - Variable Injection Local Privilege Escalation
CVE-2025-6018HIGHlocallinux28 jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
Exploit-DB
Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
CVE-2025-50481MEDIUMwebappsmultiple28 jul 2025
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RIESGO
abrir
GitHub PoC2
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RIESGO
abrir
Exploit-DB
Adobe ColdFusion 2023.6 - Remote File Read
CVE-2024-20767HIGHbajo ataquewebappsmultiple28 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC
An activity to train analysis skills and reporting
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC15
CVE-2025-53770 Mass Scanner
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
QHxDr-dz/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque27 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC2
r0otk3r/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque27 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
The POC for m6.fr website
CVE-2025-29927CRITICAL27 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque26 jul 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC
jkobierczynski/cve-2022-44268
CVE-2022-44268MEDIUM26 jul 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC3
This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to insufficient handling of crafted SMB requests. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
CVE-2024-27686HIGH26 jul 2025
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC
Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows
CVE-2025-54313HIGHbajo ataque26 jul 2025
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RIESGO
abrir
GitHub PoC
Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC
Checks projects for compromised packages, suspicious files, and import statements.
CVE-2025-54313HIGHbajo ataque26 jul 2025
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RIESGO
abrir
GitHub PoC
Report written on CVE-2024-38112
CVE-2024-38112HIGHbajo ataque25 jul 2025
Windows MSHTML Platform Spoofing Vulnerability
93RIESGO
abrir
GitHub PoC10
Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).
CVE-2025-32429CRITICAL25 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
GitHub PoC
This is my implementation of shellshock exploit
CVE-2014-6271CRITICALbajo ataque25 jul 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALbajo ataque25 jul 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL25 jul 2025
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL25 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir
anteriorpágina 222 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.