Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.198 exploits
GitHub PoC
Technical Details and Exploit for CVE-2025-50460
CVE-2025-50460CRITICAL30 jul 2025
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i
48RIESGO
abrir ↗
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALbajo ataqueransomware30 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-22809HIGH30 jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗
GitHub PoC★ 4
本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。
CVE-2025-32463CRITICALbajo ataque30 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2023-2533HIGHbajo ataque30 jul 2025
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
76RIESGO
abrir ↗
GitHub PoC★ 2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RIESGO
abrir ↗
GitHub PoC★ 1
DLL00P/CVE-2021-1675
CVE-2021-1675HIGHbajo ataqueransomware29 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
→ poc for CVE-2025-29927
CVE-2025-29927CRITICAL29 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC
classic130/CVE-2024-23897-Jenkins-4.441
CVE-2024-23897CRITICALbajo ataqueransomware29 jul 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
GitHub PoC
Ai相关
CVE-2025-54381CRITICAL29 jul 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RIESGO
abrir ↗
GitHub PoC★ 4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
CVE-2025-53770CRITICALbajo ataqueransomware29 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque29 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC★ 1
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
CVE-2021-43857CRITICAL29 jul 2025
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
CVE-2025-32463CRITICALbajo ataque29 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL29 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware29 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHbajo ataqueransomware29 jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir ↗
Exploit-DB
Xlight FTP 1.1 - Denial Of Service (DOS)
CVE-2024-0737MEDIUMdosmultiple28 jul 2025
Xlightftpd Xlight FTP Server Login denial of service
33RIESGO
abrir ↗
GitHub PoC★ 2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
CVE-2025-8191MEDIUM28 jul 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir ↗
GitHub PoC
Tools for detecting and assessing systems vulnerable to CVE-2025-53770 (CWE-502: Deserialization of Untrusted Data).
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 6
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
CVE-2025-24813CRITICALbajo ataque28 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
GitHub PoC★ 3
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RIESGO
abrir ↗
Exploit-DB
Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
CVE-2025-50481MEDIUMwebappsmultiple28 jul 2025
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RIESGO
abrir ↗
GitHub PoC★ 1
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
Exploit-DB
Linux PAM Environment - Variable Injection Local Privilege Escalation
CVE-2025-6018HIGHlocallinux28 jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗
← anteriorpágina 295 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.