Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
GitHub PoC4
How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX
CVE-2025-29774CRITICAL23 jul 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288923 jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque23 jul 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2021-45046CRITICALbajo ataqueransomware23 jul 2025
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
GitHub PoC31
Integer overflow in FreeType software, which also affects Chrome
CVE-2025-27363HIGHbajo ataque23 jul 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RIESGO
abrir
GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
CVE-2017-12637HIGHbajo ataque23 jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RIESGO
abrir
GitHub PoC
wyyazjjl/CVE-2024-45195
CVE-2024-45195CRITICALbajo ataque23 jul 2025
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
100RIESGO
abrir
GitHub PoC1
WordPress联系表单插件 - 未授权任意文件上传漏洞
CVE-2015-10137CRITICAL23 jul 2025
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
Skac44/CVE-2024-38063
CVE-2024-38063CRITICAL23 jul 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-1171423 jul 2025
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RIESGO
abrir
GitHub PoC
shan0ar/cve-2025-32756
CVE-2025-32756CRITICALbajo ataque23 jul 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
CVE-2023-44487HIGHbajo ataque23 jul 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-45046CRITICALbajo ataqueransomware23 jul 2025
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALbajo ataque23 jul 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
CVE-2025-53770CRITICALbajo ataqueransomware23 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-12637HIGHbajo ataque23 jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-27363HIGHbajo ataque23 jul 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RIESGO
abrir
GitHub PoC5
CVE-2024-4577 Mass Scanner & Exploit Tool
CVE-2024-4577CRITICALbajo ataqueransomware23 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2022-4288923 jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-4947CRITICALbajo ataque23 jul 2025
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RIESGO
abrir
GitHub PoC5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
CVE-2025-53770CRITICALbajo ataqueransomware23 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.
CVE-2024-6387HIGH23 jul 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL23 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-120722 jul 2025
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
GitHub PoC1
tripoloski1337/CVE-2025-53770-scanner
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC11
A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3408522 jul 2025
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3408522 jul 2025
35RIESGO
abrir
GitHub PoC
GreenForceNetworks/Toolshell_CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-346022 jul 2025
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
anteriorpágina 224 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.