Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
GitHub PoC48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALbajo ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque14 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir
GitHub PoC
mheranco/CVE-2025-44136
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir
GitHub PoC2
This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
CVE-2025-41656CRITICAL14 jul 2025
Pilz: Missing Authentication in Node-RED integration
53RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM14 jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-52488HIGH14 jul 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-44137HIGH14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp
56RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).
CVE-2017-0143HIGHbajo ataqueransomware13 jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALbajo ataque13 jul 2025
Remote code execution in Wazuh server
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-22457CRITICALbajo ataqueransomware13 jul 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3408513 jul 2025
35RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMbajo ataque13 jul 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
GitHub PoC2
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
CVE-2024-43425HIGH13 jul 2025
Moodle: remote code execution via calculated question types
78RIESGO
abrir
GitHub PoC14
A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-856213 jul 2025
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC8
Wazuh 8.4 CVE-2025-24016
CVE-2025-24016CRITICALbajo ataque13 jul 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC14
A detailed walkthrough of TryHackMe's Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig
CVE-2023-30258CRITICAL13 jul 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC
CVE-2025-32023
CVE-2025-32023HIGH13 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RIESGO
abrir
GitHub PoC
CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This lab is built for CTF players and bug bounty learners to simulate real-world exploitation workflows including token extraction, password reset, and flag capture.
CVE-2020-3584813 jul 2025
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RIESGO
abrir
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
CVE-2025-31125MEDIUMbajo ataque13 jul 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
GitHub PoC1
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
CVE-2013-3900MEDIUMbajo ataque12 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC1
imbas007/CVE-2025-25257
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2025-6058CRITICAL12 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-1212
CVE-2024-1212CRITICALbajo ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
anteriorpágina 230 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.