Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
75.589 exploits
GitHub PoC55
Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-20282CRITICAL01 jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
53RIESGO
abrir
GitHub PoC13
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC8
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderCMS. This tool uses PentestMonkey's PHP reverse shell script as the payload
CVE-2023-41425MEDIUM01 jul 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
CVE-2022-0847HIGHbajo ataque01 jul 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
CVE-2025-49029CRITICAL01 jul 2025
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
CVE-2025-32462LOW01 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-6218HIGHbajo ataque01 jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC1
depers-rus/CVE-2007-4559
CVE-2007-4559CRITICAL01 jul 2025
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque01 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC9
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL01 jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque01 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM01 jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RIESGO
abrir
GitHub PoC
Simulação educacional de exploração de falha em dispositivos IoT com base no CVE-2017-17761
CVE-2017-1776130 jun 2025
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 130
23RIESGO
abrir
Metasploit300
Sudo Chroot 1.9.17 Privilege Escalation
CVE-2025-32463CRITICALbajo ataque30 jun 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
Citrix Bleed 2 PoC
CVE-2025-6543CRITICALbajo ataque30 jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RIESGO
abrir
Metasploit600
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVE-2025-47812CRITICALbajo ataque30 jun 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC17
详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件
CVE-2025-5777CRITICALbajo ataqueransomware30 jun 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC2
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.
CVE-2024-40898CRITICAL30 jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1198430 jun 2025
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-6218HIGHbajo ataque29 jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-4664MEDIUM29 jun 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro
33RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2016-20016CRITICAL29 jun 2025
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH29 jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 jun 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
anteriorpágina 241 / 2520siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.