Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
GitHub PoC
VVeakee/CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RIESGO
abrir ↗GitHub PoC★ 3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir ↗Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
DataEase has database configuration information exposure vulnerability
53RIESGO
abrir ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC★ 1
cybermads/CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
Koray123-debug/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir ↗GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir ↗GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 2
CVE-2025-24813-POC JSP Web Shell Uploader
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC★ 4
simple exp for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗Exploit-DB
Next.js Middleware 15.2.2 - Authorization Bypass
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
Vite-CVE-2025-30208-EXP单目标检测,支持自定义读取路径,深度检索
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC★ 1
Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC
CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
CVE-2025-30065 PoC
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir ↗Exploit-DB
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗GitHub PoC★ 2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RIESGO
abrir ↗Exploit-DB
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
Exclusive Addons for Elementor <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
33RIESGO
abrir ↗Exploit-DB
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
IBM Security Verify Access HTTP open redirect
33RIESGO
abrir ↗Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Data plot modules) 2.4.6 - SQL Injection
SQL injection in get_chart_data in TimeProvider 4100
33RIESGO
abrir ↗Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.