Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
GitHub PoC
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
CVE-2024-52375CRITICAL22 mar 2025
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
CVE-2024-49653CRITICAL22 mar 2025
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
A PoC for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque22 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
CVE-2024-21320MEDIUMremotewindows22 mar 2025
Windows Themes Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC4
CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)
CVE-2025-24813CRITICALbajo ataque21 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque21 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
wilss0n/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware21 mar 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM21 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM21 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware21 mar 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC2
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
CVE-2025-23922CRITICAL21 mar 2025
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2016-1092421 mar 2025
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RIESGO
abrir
Metasploit300
Next.js Middleware Authorization Bypass Scanner
CVE-2025-29927CRITICAL21 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Proof-of-concept for In invoke-ai/invokeai version v5.0.2 Arbitrary File Deletion.
CVE-2024-11042CRITICAL21 mar 2025
Arbitrary File Delete in invoke-ai/invokeai
48RIESGO
abrir
GitHub PoC
The POC and Lab setup documentation of CVE 2021 41773
CVE-2021-41773HIGHbajo ataqueransomware20 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
POC for CVE-2025-24813 using Spring-Boot
CVE-2025-24813CRITICALbajo ataque20 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
CVE-2012-1823 exploit for https user password website.
CVE-2012-1823CRITICALbajo ataque20 mar 2025
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware20 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALbajo ataque20 mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque20 mar 2025
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587820 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587820 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir
Exploit-DB
JUX Real Estate 3.4.0 - SQL Injection
CVE-2025-2126MEDIUMwebappsphp20 mar 2025
JoomlaUX JUX Real Estate GET Parameter realties sql injection
33RIESGO
abrir
GitHub PoC1
minhluannguyen/CVE-2020-7247-reproducer
CVE-2020-7247CRITICALbajo ataque20 mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919320 mar 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC2
Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
CVE-2025-22954CRITICAL19 mar 2025
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi
53RIESGO
abrir
GitHub PoC2
Alternativa CVE-2025-24071_PoC
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
CVE-2018-7600.
CVE-2018-7600CRITICALbajo ataqueransomware19 mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware19 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
anteriorpágina 293 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.