Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
GitHub PoC
Reverse Shell Payload for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
GitHub PoC
This is a small script for the rce vulnerability for CVE-2025-24893. It supports basic input/output
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
Exploit-DB
Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation
CVE-2023-3460—webappsmultiple03 ago 2025
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗
GitHub PoC★ 2
Exploit SQL injection in projectworlds Online Admissions System v1.0
CVE-2025-8471MEDIUM03 ago 2025
projectworlds Online Admission System adminlogin.php sql injection
33RIESGO
abrir ↗
Exploit-DB
Swagger UI 1.0.3 - Cross-Site Scripting (XSS)
CVE-2025-8191MEDIUMremotemultiple03 ago 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2024-2782HIGH03 ago 2025
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation
56RIESGO
abrir ↗
GitHub PoC
A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.
CVE-2012-2982—03 ago 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
Exploit-DB
Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE)
CVE-2025-49683HIGHlocalwindows03 ago 2025
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability
41RIESGO
abrir ↗
Exploit-DB
LPAR2RRD 8.04 - Remote Code Execution (RCE)
CVE-2025-54769HIGHwebappsmultiple03 ago 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir ↗
GitHub PoC
dhiaZnaidi/CVE-2025-24893-PoC
CVE-2025-24893CRITICALbajo ataque03 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
GitHub PoC
Demo web server
CVE-2025-34100CRITICAL02 ago 2025
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque02 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque02 ago 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
GitHub PoC★ 3
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir ↗
GitHub PoC★ 1
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-2053HIGH02 ago 2025
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-4606CRITICAL02 ago 2025
Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
48RIESGO
abrir ↗
GitHub PoC★ 1
A critical vulnerability in Microsoft SharePoint Server allows unauthenticated remote code execution via deserialization of untrusted data. Microsoft is aware of active exploitation; apply CVE mitigations immediately. Severity: Critical.
CVE-2025-53770CRITICALbajo ataqueransomware02 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir ↗
GitHub PoC★ 1
AdnanApriliyansyahh/CVE-2022-1592
CVE-2022-1592CRITICAL02 ago 2025
Server-Side Request Forgery in scout in clinical-genomics/scout
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware02 ago 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL02 ago 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2024-21626HIGH02 ago 2025
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir ↗
GitHub PoC
CVE-2025-46811
CVE-2025-46811CRITICAL02 ago 2025
SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
53RIESGO
abrir ↗
GitHub PoC
CVE-2025-48703 là lỗ hổng mức độ nghiêm trọng trong CentOS Web Panel (CWP) cho phép kẻ tấn công không xác thực (unauthenticated) có thể thực thi mã từ xa (RCE) thông qua bỏ qua cơ chế xác thực và thực thi câu lệnh hệ thống. Lỗ hổng ảnh hưởng CWP từ phiên bản 0.9.8.1204 trở về trước, và đã được vá trên phiên bản mới nhất 0.9.8.1205.
CVE-2025-48703CRITICALbajo ataque01 ago 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RIESGO
abrir ↗
GitHub PoC★ 2
PoC for CVE-2025-41373 Authenticated SQL Injection in Gandia Integra Total v2.1.2217.3–4.4.2236.1
CVE-2025-41373HIGH01 ago 2025
SQL injection vulnerability in Gandia Integra Total
41RIESGO
abrir ↗
← anteriorpágina 293 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.