Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
75.589 exploits
GitHub PoC1
aidana-gift/CVE-2025-0868
CVE-2025-0868CRITICAL25 may 2025
Remote Code Execution in DocsGPT
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-4664MEDIUM25 may 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro
33RIESGO
abrir
VulnCheck XDB
local
CVE-2023-20963HIGHbajo ataque25 may 2025
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque25 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL25 may 2025
Authentication Bypass in GoAnywhere MFT
85RIESGO
abrir
Exploit-DB
WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass
CVE-2025-2594HIGHwebappsmultiple25 may 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RIESGO
abrir
Exploit-DB
ABB Cylon Aspect Studio 3.08.03 - Binary Planting
CVE-2024-13946HIGHlocalmultiple25 may 2025
Binary Planting / LoadLibrary DLL's not Signed
41RIESGO
abrir
GitHub PoC1
PoC CVE-2025-22457
CVE-2025-22457CRITICALbajo ataqueransomware25 may 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC7
CVE-2024-42009 Proof of Concept
CVE-2024-42009CRITICALbajo ataque24 may 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL24 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
0xWhoami35/CVE-2025-2294
CVE-2025-2294CRITICAL24 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALbajo ataque24 may 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
GitHub PoC1
davidxbors/CVE-2025-25014
CVE-2025-25014CRITICAL24 may 2025
Kibana arbitrary code execution via prototype pollution
53RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2013-478623 may 2025
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-24112CRITICALbajo ataque23 may 2025
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware23 may 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Unauthenticated Arbitrary File Read via Absolute Path
CVE-2025-46822HIGH23 may 2025
Unauthenticated Arbitrary File Read via Absolute Path
56RIESGO
abrir
GitHub PoC
enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab
CVE-2025-29927CRITICAL23 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
CVE-2025-48828CRITICAL23 may 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir
GitHub PoC
Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156
CVE-2021-3156HIGHbajo ataque23 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
encrypter15/CVE-2025-30400
CVE-2025-30400HIGHbajo ataque23 may 2025
Microsoft DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
fatkz/CVE-2022-24112
CVE-2022-24112CRITICALbajo ataque23 may 2025
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC
pouriam23/CVE-2024-12583
CVE-2024-12583CRITICAL23 may 2025
Dynamics 365 Integration <= 1.3.23 - Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
48RIESGO
abrir
Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
CVE-2025-48827CRITICAL23 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque23 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC5
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CVE-2025-31161CRITICALbajo ataqueransomware23 may 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC57
Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF
CVE-2025-4123HIGH22 may 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9463CRITICALbajo ataque22 may 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-51978CRITICAL22 may 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir
anteriorpágina 255 / 2520siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.