Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
GitHub PoC
Proof-of-concept and analysis for CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque20 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username
CVE-2025-51396MEDIUM20 jul 2025
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc
33RIESGO
abrir
GitHub PoC
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
CVE-2025-51397MEDIUM20 jul 2025
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers
33RIESGO
abrir
GitHub PoC
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Chat Name Field Triggers on Chat Owner Transfer
CVE-2025-51401MEDIUM20 jul 2025
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke
33RIESGO
abrir
GitHub PoC
PoC for CVE-2022-0492
CVE-2022-0492HIGHbajo ataque20 jul 2025
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC1
CVE-2025-48384 PoC
CVE-2025-48384HIGHbajo ataque20 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC18
A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.
CVE-2025-49706MEDIUMbajo ataqueransomware20 jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
100RIESGO
abrir
GitHub PoC
LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
CVE-2025-51403MEDIUM20 jul 2025
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.
33RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49706MEDIUMbajo ataqueransomware20 jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque20 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-41646CRITICAL19 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque19 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Anezatraa/CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque19 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2025-41646
CVE-2025-41646CRITICAL19 jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RIESGO
abrir
GitHub PoC
PoC for CVE-2024-47575
CVE-2024-47575CRITICALbajo ataque19 jul 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
GitHub PoC5
Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE
CVE-2025-25257CRITICALbajo ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
alm6no5/CVE-2024-20767
CVE-2024-20767HIGHbajo ataque19 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
GitHub PoC1
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
CVE-2025-25257CRITICALbajo ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC8
💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection
CVE-2025-49113CRITICALbajo ataque19 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC7
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
CVE-2025-24813CRITICALbajo ataque19 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC2
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
CVE-2025-7795HIGH19 jul 2025
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-20767HIGHbajo ataque19 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque19 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware19 jul 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware19 jul 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC14
PoC for NVIDIAScape bug
CVE-2025-23266CRITICAL19 jul 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHbajo ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
anteriorpágina 227 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.