Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.417exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
GitHub PoC★ 56
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
CVE-2025-50154MEDIUM13 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
45RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24054MEDIUMbajo ataque13 ago 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗
GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
CVE-2025-50428CRITICAL13 ago 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RIESGO
abrir ↗
GitHub PoC★ 7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque13 ago 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC
benguelmas/cve-2017-0143
CVE-2017-0143HIGHbajo ataqueransomware13 ago 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗
GitHub PoC★ 71
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)
CVE-2025-8088HIGHbajo ataqueransomware13 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware13 ago 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗
GitHub PoC
Dissecting CVEin Chrome
CVE-2025-5419HIGHbajo ataque13 ago 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RIESGO
abrir ↗
GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
CVE-2025-53770CRITICALbajo ataqueransomware13 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
CVE-2025-8088HIGHbajo ataqueransomware12 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC★ 1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
CVE-2025-20124CRITICAL12 ago 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RIESGO
abrir ↗
GitHub PoC★ 8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗
GitHub PoC
Program python untuk melakukan RCE pada drupal versi 7.56
CVE-2018-7600CRITICALbajo ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-53770CRITICALbajo ataqueransomware12 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-25231HIGH12 ago 2025
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RIESGO
abrir ↗
GitHub PoC★ 1
00xCanelo/CVE-2024-47533-PoC
CVE-2024-47533CRITICAL12 ago 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RIESGO
abrir ↗
GitHub PoC★ 1
PoC of CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗
GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
CVE-2017-16995—12 ago 2025
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware12 ago 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗
Exploit-DB
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
CVE-2025-53770CRITICALbajo ataqueransomwareremotewindows11 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware11 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware11 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
Exploit-DB
Ghost CMS 5.59.1 - Arbitrary File Read
CVE-2023-40028MEDIUMwebappsmultiple11 ago 2025
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque11 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
Exploit-DB
Cisco ISE 3.0 - Remote Code Execution (RCE)
CVE-2025-20124CRITICALremotemultiple11 ago 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RIESGO
abrir ↗
Exploit-DB
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
CVE-2025-7769HIGHremotemultiple11 ago 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RIESGO
abrir ↗
Exploit-DB
Microsoft Windows - Storage QoS Filter Driver Checker
CVE-2025-49730HIGHlocalwindows11 ago 2025
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
41RIESGO
abrir ↗
Exploit-DB
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
CVE-2025-41228MEDIUMwebappsmultiple11 ago 2025
VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
33RIESGO
abrir ↗
Exploit-DB
Cisco ISE 3.0 - Authorization Bypass
CVE-2025-20125CRITICALremotemultiple11 ago 2025
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
53RIESGO
abrir ↗
← anteriorpágina 288 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.