Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
75.589 exploits
VulnCheck XDB
infoleak
CVE-2025-5287HIGH31 may 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-30397HIGHbajo ataque31 may 2025
Scripting Engine Memory Corruption Vulnerability
76RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26828HIGHbajo ataque30 may 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7399HIGHbajo ataque30 may 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RIESGO
abrir
GitHub PoC
This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.
CVE-2018-15473MEDIUM30 may 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.
CVE-2017-0144HIGHbajo ataqueransomware30 may 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC5
ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
CVE-2021-26828HIGHbajo ataque30 may 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RIESGO
abrir
GitHub PoC
davidxbors/CVE-2024-7399-POC
CVE-2024-7399HIGHbajo ataque30 may 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RIESGO
abrir
GitHub PoC4
WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload
CVE-2025-47577CRITICAL30 may 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RIESGO
abrir
GitHub PoC
MQKGitHub/Moniker-Link-CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque30 may 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC11
Critical Unauthenticated API Access in vBulletin
CVE-2025-48827CRITICAL29 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
GitHub PoC
Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
CVE-2021-2291129 may 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
Exploit-DB
Windows File Explorer Windows 11 (23H2) - NTLM Hash Disclosure
CVE-2025-24071MEDIUMremotewindows29 may 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC5
nkuty/CVE-2025-30208-31125-31486-32395
CVE-2025-30208MEDIUM29 may 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
Exploit-DB
WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing
CVE-2025-4094CRITICALwebappsmultiple29 may 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RIESGO
abrir
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL29 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
Automic Agent 24.3.0 HF4 - Privilege Escalation
CVE-2025-4971HIGHremotemultiple29 may 2025
Broadcom Automic Automation Agent Unix privilege escalation
41RIESGO
abrir
Exploit-DB
Campcodes Online Hospital Management System 1.0 - SQL Injection
CVE-2025-5298MEDIUMwebappsmultiple29 may 2025
Campcodes Online Hospital Management System betweendates-detailsreports.php sql injection
33RIESGO
abrir
Exploit-DB
SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
CVE-2024-28995HIGHbajo ataqueremotemultiple29 may 2025
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 may 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291129 may 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
Exploit-DB
Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass
CVE-2024-0204CRITICALremotemultiple29 may 2025
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL29 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
GitHub PoC
thompson005/CVE-2023-22527
CVE-2023-22527CRITICALbajo ataqueransomware29 may 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH28 may 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware28 may 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-28995HIGHbajo ataque28 may 2025
SolarWinds Serv-U L Directory Transversal Vulnerability
100RIESGO
abrir
GitHub PoC2
Telerik CVE-2017-9248 Vulnerability Scanner
CVE-2017-9248CRITICALbajo ataque28 may 2025
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC3
Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.
CVE-2025-24071MEDIUM28 may 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
anteriorpágina 253 / 2520siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.