Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.565exploits catalogados
34.501CVEs con explotación pública
24.695probados en laboratorio
75.565 exploits
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware08 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware08 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-7954
CVE-2024-7954CRITICAL08 jul 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege
CVE-2025-32462LOWlocallinux08 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC1
# cve-2025-32463 - Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALbajo ataque08 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC3
0xtensho/CVE-2025-49132-poc
CVE-2025-49132CRITICAL08 jul 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
lowercasenumbers/CVE-2025-32463_sudo_chroot
CVE-2025-32463CRITICALbajo ataque08 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque08 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC5
Docker PoC for CVE-2025-32462 & CVE-2025-32463 (sudo), based on Stratascale CRU research.
CVE-2025-32462LOW07 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC
Exploit for CVE-2025-47812 with custom psudo shell and robust error handling.
CVE-2025-47812CRITICALbajo ataque07 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALbajo ataque07 jul 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir
GitHub PoC2
Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit
CVE-2024-9264CRITICAL07 jul 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque07 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
Exploit CVE-2025-24071
CVE-2025-24071MEDIUM07 jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
r0otk3r/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware07 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC2
PwnToday/CVE-2025-6554
CVE-2025-6554HIGHbajo ataque07 jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RIESGO
abrir
GitHub PoC
LibSSH authentification bypass
CVE-2018-10933CRITICAL07 jul 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC3
ibrahmsql/CVE-2024-47773
CVE-2024-47773HIGH07 jul 2025
Anonymous cache poisoning via XHR requests in Discourse
41RIESGO
abrir
GitHub PoC
POC
CVE-2025-24813CRITICALbajo ataque07 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque07 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware07 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque07 jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Script Bash -- CVE-2021-3560
CVE-2021-3560HIGHbajo ataque07 jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL06 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2564606 jul 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
GitHub PoC
Citrix Bleed 2 PoC Scanner (CVE-2025-5777)
CVE-2025-5777CRITICALbajo ataqueransomware06 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC2
CitrixBleed-2 Checker & Poc automatic exploit and check token.
CVE-2025-5777CRITICALbajo ataqueransomware06 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC216
PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
CVE-2025-32023HIGH06 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque06 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 jul 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
anteriorpágina 235 / 2519siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.