Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
GitHub PoC1
imbas007/CVE-2025-53770-Vulnerable-Scanner
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)
CVE-2025-6082MEDIUM22 jul 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RIESGO
abrir
Exploit-DB
Discourse 3.1.1 - Unauthenticated Chat Message Access
CVE-2023-45131HIGHwebappsmultiple22 jul 2025
Unauthenticated access to new private chat messages in Discourse
41RIESGO
abrir
GitHub PoC
KiPhuong/cve-2024-3552
CVE-2024-3552CRITICAL22 jul 2025
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RIESGO
abrir
Exploit-DB
Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
CVE-2025-7795HIGHremotemultiple22 jul 2025
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RIESGO
abrir
GitHub PoC1
PoC exploit for CVE-2025-47917: Use-After-Free in mbedTLS leading to remote code execution.
CVE-2025-47917HIGH22 jul 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RIESGO
abrir
GitHub PoC
cve-2024-32002
CVE-2024-32002CRITICAL22 jul 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque22 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-713922 jul 2025
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
WordPress WPBookit ≤ 1.0.4 Unauthenticated File Upload Exploit
CVE-2025-6058CRITICAL22 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware22 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Gogs Under Attack: Unpacking the Critical SSH Vulnerability (CVE-2024–39930)
CVE-2024-39930CRITICAL22 jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RIESGO
abrir
GitHub PoC
JinParkmida/cve-2023-28771-demo
CVE-2023-28771CRITICALbajo ataque22 jul 2025
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir
GitHub PoC1
gmh5225/CVE-2025-6558-exp
CVE-2025-6558HIGHbajo ataque22 jul 2025
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-282522 jul 2025
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-346022 jul 2025
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-138622 jul 2025
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3408522 jul 2025
35RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque22 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-120722 jul 2025
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-120722 jul 2025
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3408522 jul 2025
35RIESGO
abrir
Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
CVE-2025-51401MEDIUMwebappsphp22 jul 2025
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke
33RIESGO
abrir
Exploit-DB
Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
CVE-2015-6176remotewindows22 jul 2025
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site script
28RIESGO
abrir
Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
CVE-2025-51403MEDIUMwebappsphp22 jul 2025
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.
33RIESGO
abrir
Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages
CVE-2025-51400MEDIUMwebappsphp22 jul 2025
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac
33RIESGO
abrir
Exploit-DB
Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
CVE-2020-36847CRITICALwebappsmultiple22 jul 2025
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir
anteriorpágina 225 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.