Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.951exploits catalogados
34.636CVEs con explotación pública
24.695probados en laboratorio
75.951 exploits
GitHub PoC2
sandsoncosta/CVE-2025-26633
CVE-2025-26633HIGHbajo ataqueransomware08 abr 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL08 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
local
CVE-2025-26633HIGHbajo ataqueransomware08 abr 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware08 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2020-7656webappsmultiple08 abr 2025
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-22457CRITICALbajo ataqueransomware08 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque08 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
CVE-2019-15949HIGHbajo ataquewebappsmultiple08 abr 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-22457CRITICALbajo ataqueransomware08 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
CVE-2024-56902HIGHwebappsmultiple08 abr 2025
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-282508 abr 2025
35RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-44308HIGHbajo ataque07 abr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RIESGO
abrir
GitHub PoC
DFG register allocation bug in JavaScriptCore
CVE-2024-44308HIGHbajo ataque07 abr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-5418HIGHbajo ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC
vances25/CVE-2024-44871
CVE-2024-44871HIGH07 abr 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RIESGO
abrir
GitHub PoC3
mouadk/parquet-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL07 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir
GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
CVE-2019-5418HIGHbajo ataque07 abr 2025
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
CVE-2025-24813CRITICALbajo ataquewebappsmultiple07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Heimd411/CVE-2025-24813-noPoC
CVE-2025-24813CRITICALbajo ataque07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
CVE-2025-24893CRITICALbajo ataquewebappsmultiple07 abr 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
CVE-2025-31131HIGHwebappsmultiple07 abr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-23397CRITICALbajo ataque07 abr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL07 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
CVE-2025-29927
CVE-2025-29927CRITICAL07 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
CVE-2023-23397CRITICALbajo ataque07 abr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC32
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHbajo ataque06 abr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALbajo ataque06 abr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
GitHub PoC8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
cybermads/CVE-2011-2523
CVE-2011-252306 abr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
anteriorpágina 280 / 2532siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.