Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
VulnCheck XDB
initial-access
CVE-2025-52970HIGH07 sep 2025
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
61RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains how attackers can escape container boundaries, compromise AI workloads, and how tools like Sentinel can detect and mitigate the threat
CVE-2025-23266CRITICAL07 sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque07 sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC★ 3
This is CVE-2025-53690 Analysis Documents.
CVE-2025-53690CRITICALbajo ataque07 sep 2025
Sitecore Products ViewState Deserialization Vulnerability
90RIESGO
abrir ↗
GitHub PoC★ 11
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
CVE-2025-7771HIGH07 sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
GitHub PoC★ 3
PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.
CVE-2025-32433CRITICALbajo ataque07 sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC
MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
CVE-2017-5638CRITICALbajo ataqueransomware06 sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗
GitHub PoC★ 2
PoC for CVE-2015-5736
CVE-2015-5736—06 sep 2025
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RIESGO
abrir ↗
GitHub PoC
This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
GitHub PoC
tranphuc2005/CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware06 sep 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
GitHub PoC★ 3
This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALbajo ataque06 sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-54309CRITICALbajo ataque06 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-58443CRITICAL06 sep 2025
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir ↗
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC
cve-2025-33073/cve-2025-33073
CVE-2025-33073HIGHbajo ataque06 sep 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware06 sep 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir ↗
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
CVE-2022-44262CRITICAL06 sep 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RIESGO
abrir ↗
GitHub PoC★ 6
exploit SQL injection ELEX WooCommerce Google Shopping
CVE-2025-10046MEDIUM06 sep 2025
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RIESGO
abrir ↗
GitHub PoC
oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
CVE-2013-3900MEDIUMbajo ataque06 sep 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗
GitHub PoC
whisperer1290/CVE-2025-54309__Enhanced_exploit
CVE-2025-54309CRITICALbajo ataque06 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
GitHub PoC★ 2
FOGProject Authentication bypass CVE-2025-58443 Exploit
CVE-2025-58443CRITICAL06 sep 2025
FOG's authentication bypass leads to full SQL DB dump
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware05 sep 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
GitHub PoC
andwati/CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque05 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque05 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC
blackcat4347/CVE-2025-32463_PoC
CVE-2025-32463CRITICALbajo ataque05 sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC
Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal + RCE (CVE-2021-42013) en servidores mal configurados.
CVE-2021-42013CRITICALbajo ataqueransomware05 sep 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗
GitHub PoC★ 1
Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation
CVE-2025-49388CRITICAL05 sep 2025
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
48RIESGO
abrir ↗
← anteriorpágina 276 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.