Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
GitHub PoC3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque28 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2775CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALbajo ataqueransomware28 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
CVE-2024-44000CRITICALwebappsphp28 mar 2025
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALbajo ataque28 mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2777CRITICAL28 mar 2025
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CVE-2024-8945MEDIUMwebappsphp28 mar 2025
CodeCanyon RISE Ultimate Project Manager save sql injection
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2776CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir
GitHub PoC7
CVE-2025-29927에 대한 설명 및 리서치
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-30349HIGH27 mar 2025
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RIESGO
abrir
Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
CVE-2024-46528MEDIUMwebappsmultiple27 mar 2025
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RIESGO
abrir
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2021-44228CRITICALbajo ataqueransomware27 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Heimd411/CVE-2025-29927-PoC
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL27 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC2
Next.js CVE-2025-29927 Vulnerability Scanner
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208MEDIUM27 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC
IngressNightmare (CVE-2025-1974)
CVE-2025-1974CRITICAL27 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
GitHub PoC1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
CVE-2025-29927CRITICAL27 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
anteriorpágina 287 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.