Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
GitHub PoC★ 3
Create lab for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC★ 92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 3
CVE-2025-29927: Next.js Middleware Exploit
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
This repository is for educational and research purposes.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RIESGO
abrir ↗Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CodeCanyon RISE Ultimate Project Manager save sql injection
38RIESGO
abrir ↗VulnCheck XDB
initial-access
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir ↗VulnCheck XDB
client-side
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RIESGO
abrir ↗Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RIESGO
abrir ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC★ 10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗GitHub PoC
IngressNightmare (CVE-2025-1974)
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗GitHub PoC★ 1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.