Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque18 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-47176HIGH18 jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RIESGO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque18 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHbajo ataque18 jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RIESGO
abrir
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHbajo ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHbajo ataque17 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque17 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque17 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
CVE-2025-49677HIGHlocalwindows16 jul 2025
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC1
krypton-0x00/CVE-2025-32463-Chwoot-POC
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
CVE-2024-11605MEDIUMwebappsmultiple16 jul 2025
WP Publications <= 1.2 - Admin+ Stored XSS
33RIESGO
abrir
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
CVE-2025-3248CRITICALbajo ataqueransomwarewebappsmultiple16 jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
CVE-2025-49744HIGHlocalwindows16 jul 2025
Windows Graphics Component Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Detection for CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque16 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Exploit-DB
NodeJS 24.x - Path Traversal
CVE-2025-27210HIGHremotenodejs16 jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
41RIESGO
abrir
Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
CVE-2024-58258HIGHwebappsmultiple16 jul 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque16 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware16 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque16 jul 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
CVE-2025-1550HIGHremotepython16 jul 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RIESGO
abrir
anteriorpágina 228 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.