Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
75.902 exploits
GitHub PoC
Updated exploit script for the CVE-2021-43798
CVE-2021-43798HIGHbajo ataque27 abr 2025
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288927 abr 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-8291HIGHbajo ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
shun1403/PIL-CVE-2017-8291-study
CVE-2017-8291HIGHbajo ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
shun1403/CVE-2017-8291
CVE-2017-8291HIGHbajo ataque27 abr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
CVE-2025-1974CRITICAL27 abr 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC
CVE-2025-32433 Summary and Attack Overview
CVE-2025-32433CRITICALbajo ataque27 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Attacks a vulnerable WordPress site with the wp-automatic plugin. Inserts a new user called eviladmin directly into the database (INSERT INTO wp_users). Searches for the ID of the newly created user (cyclic SELECT). Promotes eviladmin to Administrator (INSERT INTO wp_usermeta).
CVE-2024-27956CRITICAL27 abr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RIESGO
abrir
GitHub PoC2
CVE-2022-3552 RCE with detailed exploitation steps
CVE-2022-3552HIGH27 abr 2025
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RIESGO
abrir
GitHub PoC1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 abr 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHbajo ataqueransomware26 abr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-1389HIGHbajo ataque26 abr 2025
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL26 abr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RIESGO
abrir
GitHub PoC10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALbajo ataque26 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-41773HIGHbajo ataqueransomware26 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 abr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
CVE-2016-209825 abr 2025
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC5
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
CVE-2025-29306CRITICAL25 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALbajo ataque25 abr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3102HIGH25 abr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 abr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware25 abr 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHbajo ataqueransomware25 abr 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHbajo ataque25 abr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RIESGO
abrir
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-011425 abr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-32433CRITICALbajo ataque25 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
anteriorpágina 267 / 2531siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.