Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
GitHub PoC★ 18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC★ 1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RIESGO
abrir ↗
GitHub PoC★ 19
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALbajo ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC★ 2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALbajo ataque31 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware30 ago 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗
GitHub PoC
Aaqilyousuf/CVE-2025-7775-vulnerable-lab
CVE-2025-7775CRITICALbajo ataque30 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir ↗
GitHub PoC
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALbajo ataque30 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
GitHub PoC★ 5
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
CVE-2025-24201CRITICALbajo ataque30 ago 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque30 ago 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir ↗
GitHub PoC★ 6
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
CVE-2025-57819CRITICALbajo ataque30 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC
tranphuc2005/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware30 ago 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗
GitHub PoC★ 4
PHPUnit CVE-2017-9841 Scanner in Go clean and fire.
CVE-2017-9841CRITICALbajo ataque30 ago 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir ↗
GitHub PoC
CrushFTP AS2 Authentication Bypass
CVE-2025-54309CRITICALbajo ataque29 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
GitHub PoC
Python Script for CVE-2025-49113. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2025-49113CRITICALbajo ataque29 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque29 ago 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
GitHub PoC
arun1033/CVE-2025-48384
CVE-2025-48384HIGHbajo ataque29 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
GitHub PoC★ 2
致远OA存在文件上传导致RCE(CVE-2025-34040)
CVE-2025-34040CRITICAL29 ago 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque29 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
GitHub PoC
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque29 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-34040CRITICAL29 ago 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque28 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC★ 1
soltanali0/CVE-2024-12877-Exploit
CVE-2024-12877CRITICAL28 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir ↗
GitHub PoC★ 11
IOS audio buffer overflow CVE-2025-31200 POC
CVE-2025-31200CRITICALbajo ataque28 ago 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RIESGO
abrir ↗
GitHub PoC
Naved124/CVE-2024-28397-js2py-Sandbox-Escape
CVE-2024-28397MEDIUM28 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
CVE-2025-57819CRITICALbajo ataque28 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-12877CRITICAL28 ago 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RIESGO
abrir ↗
GitHub PoC★ 1
Detection for CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque28 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 ago 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
← anteriorpágina 279 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.