Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
75.589 exploits
GitHub PoC
The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on the server. By supplying a crafted URL that hosts a reverse shell payload, an attacker can gain command execution.
CVE-2019-9978MEDIUMbajo ataque19 may 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMbajo ataque19 may 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
Exploit-DB
Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
CVE-2025-1731HIGHlocalmultiple18 may 2025
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware
41RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALbajo ataqueransomware18 may 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-44258HIGH18 may 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RIESGO
abrir
Exploit-DB
CrushFTP 11.3.1 - Authentication Bypass
CVE-2025-31161CRITICALbajo ataqueransomwareremotemultiple18 may 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
Exploit-DB
Invision Community 5.0.6 - Remote Code Execution (RCE)
CVE-2025-47916CRITICALremotemultiple18 may 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
GitHub PoC4
Designed for Demonstration of Deep Exploitation.
CVE-2025-32756CRITICALbajo ataque18 may 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC
Mitel MiCollab Authentication Bypass to Arbitrary File Read
CVE-2024-41713CRITICALbajo ataqueransomware18 may 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALbajo ataque18 may 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
VulnCheck XDB
local
CVE-2025-0288HIGH17 may 2025
CVE-2025-0288
41RIESGO
abrir
GitHub PoC
Automation Exploit
CVE-2021-4034HIGHbajo ataque17 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
CVE-2020-1472MEDIUMbajo ataqueransomware17 may 2025
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC4
Eventin <= 4.0.26 - Missing Authorization to Unauthenticated Privilege Escalation
CVE-2025-47539CRITICAL17 may 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
GitHub PoC
tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo
CVE-2020-0796CRITICALbajo ataqueransomware17 may 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC200
CVE-2025-31200 is a zero-day, zero-click RCE in iOS CoreAudio’s AudioConverterService, triggered by a malicious audio file via iMessage/SMS. Exploitation bypassed Blastdoor, enabled kernel escalation (CVE-2025-31201), and allowed token theft until patched in iOS 18.4.1 (Apr 16, 2025).
CVE-2025-31200CRITICALbajo ataque17 may 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47539CRITICAL17 may 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
GitHub PoC
PenguinCabinet/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM16 may 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-4428HIGHbajo ataque16 may 2025
Remote Code Execution
100RIESGO
abrir
GitHub PoC4
Ivanti EPMM Pre-Auth RCE Chain
CVE-2025-4428HIGHbajo ataque16 may 2025
Remote Code Execution
100RIESGO
abrir
GitHub PoC2
WordPress PSW Front-end Login &amp; Registration Plugin <= 1.12 is vulnerable to Broken Authentication
CVE-2025-47646CRITICAL16 may 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RIESGO
abrir
GitHub PoC2
GadaLuBau1337/CVE-2025-32583
CVE-2025-32583CRITICAL16 may 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque16 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
CVE-2022-41082HIGHbajo ataqueransomware16 may 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability
CVE-2021-4034HIGHbajo ataque16 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Metasploit600
Invision Community 5.0.6 customCss RCE
CVE-2025-47916CRITICAL16 may 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
GitHub PoC
Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment
CVE-2023-20198CRITICALbajo ataque15 may 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC11
watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
CVE-2025-4427MEDIUMbajo ataque15 may 2025
Authentication Bypass
100RIESGO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2025-3605
CVE-2025-3605CRITICAL15 may 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
GitHub PoC2
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)
CVE-2025-4094CRITICAL15 may 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RIESGO
abrir
anteriorpágina 257 / 2520siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.