Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
VulnCheck XDB
remote-with-credentials
CVE-2019-15949HIGHbajo ataque26 nov 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque26 nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
CVE-2021-41773HIGHbajo ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware26 nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6389CRITICAL25 nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-6554HIGHbajo ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RIESGO
abrir
Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
CVE-2025-58360HIGHbajo ataque25 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
CVE-2022-37969HIGHbajo ataqueransomware25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
CVE-2024-29943CRITICAL25 nov 2025
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RIESGO
abrir
GitHub PoC31
aklnjakln/CVE-2025-6554
CVE-2025-6554HIGHbajo ataque25 nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataqueransomware25 nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
CVE-2025-62168CRITICAL25 nov 2025
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RIESGO
abrir
GitHub PoC
CVE-2025-61757
CVE-2025-61757CRITICALbajo ataque25 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir
GitHub PoC
CVE-2012-2122 MySQL Authentication Bypass Home Lab
CVE-2012-212224 nov 2025
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
CVE-2023-36845CRITICALbajo ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
GitHub PoC
IS8123/CVE-2025-54381
CVE-2025-54381CRITICAL24 nov 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir
VulnCheck XDB
local
CVE-2025-11001HIGH24 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALbajo ataque24 nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-845124 nov 2025
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
GitHub PoC
CVE-2025-12762
CVE-2025-12762CRITICAL24 nov 2025
Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53RIESGO
abrir
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir
GitHub PoC
CVE-2025-41115
CVE-2025-41115CRITICAL24 nov 2025
Incorrect privilege assignment
53RIESGO
abrir
GitHub PoC1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
CVE-2017-0199HIGHbajo ataqueransomware23 nov 2025
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
CVE-2025-24054MEDIUMbajo ataque23 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
rashedhasan090/CVE-2025-5777
CVE-2025-5777CRITICALbajo ataqueransomware23 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware23 nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-24054MEDIUMbajo ataque23 nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
CVE-2025-11833 Checker
CVE-2025-11833CRITICAL23 nov 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RIESGO
abrir
GitHub PoC1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
CVE-2025-10230CRITICAL23 nov 2025
Samba: command injection in wins server hook script
60RIESGO
abrir
GitHub PoC
Custom Docker Image
CVE-2017-7494CRITICALbajo ataqueransomware22 nov 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
anteriorpágina 250 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.