Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALbajo ataqueransomware19 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Resources for teh Apache Tomcat CVE lab
CVE-2025-24813CRITICALbajo ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
CVE-2023-0159webappsphp19 mar 2025
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RIESGO
abrir
Metasploit600
ICTBroadcast Unauthenticated Remote Code Execution
CVE-2025-2611CRITICAL19 mar 2025
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587819 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir
GitHub PoC2
Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
CVE-2025-22954CRITICAL19 mar 2025
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi
53RIESGO
abrir
GitHub PoC2
Alternativa CVE-2025-24071_PoC
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
CVE-2018-7600.
CVE-2018-7600CRITICALbajo ataqueransomware19 mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
CVE-2025-24071MEDIUM18 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC1
Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
CVE-2025-30066HIGHbajo ataque18 mar 2025
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
93RIESGO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL18 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
Exploit-DB
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
CVE-2023-4220HIGHwebappsphp18 mar 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC6
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC7
Otsmane-Ahmed/cve-2025-29384-poc
CVE-2025-29384CRITICAL18 mar 2025
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability
48RIESGO
abrir
GitHub PoC1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
CVE-2023-41991MEDIUMbajo ataque18 mar 2025
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RIESGO
abrir
GitHub PoC2
CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the router's root account. This means a default, unchanging password is built into the router's software.
CVE-2024-57040CRITICAL18 mar 2025
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-57040CRITICAL18 mar 2025
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
CVE-2024-56249CRITICAL18 mar 2025
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-1661CRITICAL18 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM18 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHbajo ataque18 mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHbajo ataque18 mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587817 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir
Metasploit600
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
CVE-2024-12971HIGH17 mar 2025
QuickShell Authenticated Command Injection
48RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque17 mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC3
Nuclei Template CVE-2025–24813
CVE-2025-24813CRITICALbajo ataque17 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
anteriorpágina 294 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.