Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque16 nov 2025
Incorrect Authorization in Graphics
71RIESGO
abrir ↗
GitHub PoC★ 1
Twodimensionalitylevelcrossing817/CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque15 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.
CVE-2019-9053—15 nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.
CVE-2025-64328HIGHbajo ataque15 nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RIESGO
abrir ↗
GitHub PoC
Detection, Exploit and Mitigation for CVE 2023 46604.
CVE-2023-46604CRITICALbajo ataqueransomware15 nov 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque15 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque15 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
GitHub PoC★ 13
soltanali0/CVE-2025-64446-Exploit
CVE-2025-64446CRITICALbajo ataque15 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHbajo ataque15 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-9316MEDIUM14 nov 2025
N-central unauthenticated sessionID generation
60RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
GitHub PoC★ 67
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHbajo ataque14 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-11700HIGH14 nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-62215HIGHbajo ataque14 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-33073HIGHbajo ataque14 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
CVE-2022-22965CRITICALbajo ataque14 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗
GitHub PoC★ 67
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHbajo ataque14 nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
Metasploit300
Fortinet FortiWeb create new local admin
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-58034MEDIUMbajo ataque14 nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir ↗
GitHub PoC★ 32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
CVE-2025-62215HIGHbajo ataque14 nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RIESGO
abrir ↗
GitHub PoC★ 13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
GitHub PoC★ 1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
CVE-2025-64513CRITICAL14 nov 2025
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RIESGO
abrir ↗
GitHub PoC★ 7
PoC de CVE-2025-64446: path traversal a RCE en Fortinet FortiWeb. Solo uso educativo.
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque14 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗
GitHub PoC
keyuraghao/CVE-2025-20260
CVE-2025-20260CRITICAL13 nov 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RIESGO
abrir ↗
GitHub PoC
cyhe50/cve-2025-32434-poc
CVE-2025-32434CRITICAL13 nov 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware13 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-7771HIGH13 nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
← anteriorpágina 254 / 2698siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.