Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware12 jul 2025
Information disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.
CVE-2025-24813CRITICALbajo ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
imbas007/CVE-2025-25257
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
CVE-2013-3900MEDIUMbajo ataque12 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-1212
CVE-2024-1212CRITICALbajo ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
GitHub PoC1
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1212CRITICALbajo ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque11 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
just remeber how small mistake in santisize username could give yoy root access to the full machine
CVE-2007-244711 jul 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-4577CRITICALbajo ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque11 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-4577CRITICALbajo ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware11 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC
Rust PoC for CVE-2025-32463 (sudo chroot "chwoot" Local PrivEsc)
CVE-2025-32463CRITICALbajo ataque11 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALbajo ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
CVE-2024-32113 & CVE-2024-38856
CVE-2024-32113CRITICALbajo ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers
CVE-2024-4577CRITICALbajo ataqueransomware11 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
CVE-2025-32462LOW11 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC
Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE
CVE-2022-36934CRITICAL11 jul 2025
An integer overflow in WhatsApp could result in remote code execution in an established video call.
48RIESGO
abrir
GitHub PoC
hackmelocal/CVE-2025-49113-Simulation
CVE-2025-49113CRITICALbajo ataque11 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
cuijiung/log4j-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware11 jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
PoC dockerfile image for CVE-2025-48384
CVE-2025-48384HIGHbajo ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RIESGO
abrir
GitHub PoC
p1026/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque11 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
anteriorpágina 231 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.