Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
GitHub PoC
Jenkins CLI arbitrary file read (CVE-2024-23897)
CVE-2024-23897CRITICALbajo ataqueransomware10 sep 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC
This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”)
CVE-2025-54236CRITICALbajo ataque10 sep 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir ↗
GitHub PoC★ 1
Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and fail2ban evasion techniques. Professional-grade security testing framework for authorized penetration testing engagements.
CVE-2018-15473MEDIUM10 sep 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗
GitHub PoC
Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
CVE-2025-49113CRITICALbajo ataque10 sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-4956HIGH10 sep 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
GitHub PoC
This repository contains the corrected code for CVE: 2019-9053
CVE-2019-9053—09 sep 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗
GitHub PoC
FuelCMS 1.4.1 Command Injection/Remote Code Execution.
CVE-2018-16763—09 sep 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗
GitHub PoC
PoC Script for the CVE-2018-11776 vuln
CVE-2018-11776HIGHbajo ataque09 sep 2025
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware09 sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC
Log4Shell CVE-2021-44228 PoC
CVE-2021-44228CRITICALbajo ataqueransomware09 sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC
In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses sanitization and is later executed by OctoPrint’s event system, leading to remote code execution (RCE) on the host
CVE-2025-58180HIGH09 sep 2025
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
46RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-16763—09 sep 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque09 sep 2025
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗
GitHub PoC★ 12
This repository contains a python exploit code for CVE-2024-28397 intended for use on the "CodePartTwo" machine on Hack The Box (HTB).
CVE-2024-28397MEDIUM09 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC
script de enumeración de usuarios SSH basado en diferencias de timing y respuestas de autenticación. Explota el mismo vector que CVE-2018-15473 en versiones vulnerables de OpenSSH (≤ 7.7), aunque también puede revelar patrones en configuraciones modernas.
CVE-2018-15473MEDIUM09 sep 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗
Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
CVE-2025-60787HIGH09 sep 2025
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir ↗
GitHub PoC★ 6
CVE-2025-43300: iOS/macOS DNG Image Processing Memory Corruption
CVE-2025-43300CRITICALbajo ataque09 sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The article explains how a missing privilege check in the “GetRouteTable” API enables lateral movement and remote exploitation, urging immediate patching and monitoring
CVE-2025-54914CRITICAL08 sep 2025
Azure Networking Elevation of Privilege Vulnerability
48RIESGO
abrir ↗
GitHub PoC★ 1
Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware08 sep 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-6387
CVE-2024-6387HIGH08 sep 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗
GitHub PoC
Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecución remota de código (RCE) en Apache Tomcat (CVE-2025-24813).
CVE-2025-24813CRITICALbajo ataque08 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque08 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque08 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC
boriitoo/CVE-2012-2982
CVE-2012-2982—08 sep 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-21333HIGHbajo ataque08 sep 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM08 sep 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
GitHub PoC
CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque08 sep 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗
GitHub PoC★ 11
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
CVE-2025-7771HIGH07 sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-7771HIGH07 sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-52970HIGH07 sep 2025
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
61RIESGO
abrir ↗
← anteriorpágina 275 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.