Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
75.589 exploits
VulnCheck XDB
info-leak
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir ↗VulnCheck XDB
client-side
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro
33RIESGO
abrir ↗GitHub PoC★ 1
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC★ 1
POC for PDF JS' CVE-2024-4367 vuln
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗GitHub PoC
aninfosec/CVE-2024-43425-Poc
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗GitHub PoC★ 1
obscura-cert/CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗GitHub PoC
obscura-cert/CVE-2025-31650
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir ↗VulnCheck XDB
client-side
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir ↗Metasploit600
PandoraFMS Netflow Authenticated Remote Code Execution
Command Injection in Netflow path
41RIESGO
abrir ↗Metasploit300
Marvell QConvergeConsole Path Traversal (CVE-2025-6793)
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
48RIESGO
abrir ↗GitHub PoC★ 1
Security analysis project: Real-world CVE breakdown
Xz: malicious code in distributed source
70RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-concept and analysis for CVE-2025-32711
M365 Copilot Information Disclosure Vulnerability
48RIESGO
abrir ↗GitHub PoC★ 21
Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 17
speinador/CVE-2025-6218_WinRAR
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RIESGO
abrir ↗GitHub PoC★ 10
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to extract potentially sensitive information from server memory over the TLS protocol.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
Escala de privilegios con CVE-2010-5195
Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9
23RIESGO
abrir ↗Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RIESGO
abrir ↗VulnCheck XDB
initial-access
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir ↗Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗GitHub PoC★ 7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.