Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.526 exploits
GitHub PoC★ 1
imbas007/CVE-2025-53770-Vulnerable-Scanner
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RIESGO
abrir ↗Exploit-DB
Discourse 3.1.1 - Unauthenticated Chat Message Access
Unauthenticated access to new private chat messages in Discourse
41RIESGO
abrir ↗GitHub PoC
KiPhuong/cve-2024-3552
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RIESGO
abrir ↗Exploit-DB
Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RIESGO
abrir ↗GitHub PoC★ 1
PoC exploit for CVE-2025-47917: Use-After-Free in mbedTLS leading to remote code execution.
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RIESGO
abrir ↗GitHub PoC
cve-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir ↗GitHub PoC
CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
infoleak
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca
43RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
WordPress WPBookit ≤ 1.0.4 Unauthenticated File Upload Exploit
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Gogs Under Attack: Unpacking the Critical SSH Vulnerability (CVE-2024–39930)
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RIESGO
abrir ↗GitHub PoC
JinParkmida/cve-2023-28771-demo
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir ↗GitHub PoC★ 1
gmh5225/CVE-2025-6558-exp
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RIESGO
abrir ↗VulnCheck XDB
initial-access
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke
33RIESGO
abrir ↗Exploit-DB
Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site script
28RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.
33RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac
33RIESGO
abrir ↗Exploit-DB
Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.