Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
GitHub PoC★ 1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
CVE-2007-2447—13 sep 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALbajo ataque12 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.
CVE-2024-3094CRITICAL12 sep 2025
Xz: malicious code in distributed source
70RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-4123HIGH12 sep 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir ↗
GitHub PoC★ 1
JinhyukKo/CVE-2024-4701-POC
CVE-2024-4701CRITICAL12 sep 2025
Path Traversal vulnerability via File Uploads in Genie
53RIESGO
abrir ↗
GitHub PoC★ 8
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
CVE-2025-57819CRITICALbajo ataque12 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC★ 4
Ash1996x/CVE-2025-54914-PoC
CVE-2025-54914CRITICAL12 sep 2025
Azure Networking Elevation of Privilege Vulnerability
48RIESGO
abrir ↗
GitHub PoC
Grafana CVE-2025-4123-POC
CVE-2025-4123HIGH12 sep 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir ↗
GitHub PoC
GIT vulnerability | Carriage Return and RCE on cloning
CVE-2025-48384HIGHbajo ataque12 sep 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
GitHub PoC
Detection for CVE-2025-42944
CVE-2025-42944CRITICAL11 sep 2025
Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
48RIESGO
abrir ↗
GitHub PoC
A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos
CVE-2017-5638CRITICALbajo ataqueransomware11 sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗
GitHub PoC★ 1
In-depth study of CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX. Covers .NET deserialization vulnerability, RadAsyncUpload handler, gadget chains, mixed-mode assembly exploitation, and mitigation strategies.
CVE-2019-18935CRITICALbajo ataqueransomware11 sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir ↗
GitHub PoC
exploit of CVE-2022-0847 which directly remove password of the root account
CVE-2022-0847HIGHbajo ataque11 sep 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware11 sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware11 sep 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
GitHub PoC★ 1
For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.
CVE-2021-4034HIGHbajo ataqueransomware11 sep 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque11 sep 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL11 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC
This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.
CVE-2025-29927CRITICAL11 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware10 sep 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC★ 4
CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full control. The article explains the vulnerability, threat model, provides minimal exploit ABAP code, and lists patching & monitoring steps to secure the system
CVE-2025-42957CRITICAL10 sep 2025
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RIESGO
abrir ↗
GitHub PoC
This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”)
CVE-2025-54236CRITICALbajo ataque10 sep 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir ↗
GitHub PoC
Nexus Repository 3 Path Traversal (CVE-2024-4956)
CVE-2024-4956HIGH10 sep 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
GitHub PoC
CVE-2025-24893 RCE exploit for XWiki with reverse shell capability
CVE-2025-24893CRITICALbajo ataque10 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
GitHub PoC★ 2
PoC CVE-2025-31161 - Authentication Bypass CrushFTP
CVE-2025-31161CRITICALbajo ataqueransomware10 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware10 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
GitHub PoC
Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
CVE-2025-49113CRITICALbajo ataque10 sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
GitHub PoC
To check for vulnerability CVE-2019-13272
CVE-2019-13272HIGHbajo ataque10 sep 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗
GitHub PoC
Jenkins CLI arbitrary file read (CVE-2024-23897)
CVE-2024-23897CRITICALbajo ataqueransomware10 sep 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC
Linux privilege escalation using Dirty COW exploit (CVE-2016-5195).
CVE-2016-5195HIGHbajo ataque10 sep 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗
← anteriorpágina 274 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.