Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
GitHub PoC1
Security Researcher
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC3
CVE-2025-24813_POC
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC196
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
User name enumeration against SSH daemons affected by CVE-2016-6210.
CVE-2016-6210MEDIUM14 mar 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC11
cve-2025-24813验证脚本
CVE-2025-24813CRITICALbajo ataque14 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
CVE-2012-298214 mar 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC
redpack-kr/CVE-2025-26319
CVE-2025-26319CRITICAL14 mar 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RIESGO
abrir
Metasploit300
Sante PACS Server Path Traversal (CVE-2025-2264)
CVE-2025-2264HIGH13 mar 2025
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RIESGO
abrir
GitHub PoC1
HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC
CVE-2025-1661CRITICAL13 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque13 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque13 mar 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
CVE-2025-27007CRITICAL13 mar 2025
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-1661CRITICAL13 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
CVE-2025-3102HIGH13 mar 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL13 mar 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RIESGO
abrir
GitHub PoC43
This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.
CVE-2019-2215HIGHbajo ataque13 mar 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC98
Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)
CVE-2025-24813CRITICALbajo ataque13 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL12 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
GitHub PoC1
POC for CVE-2025-26240
CVE-2025-26240HIGH12 mar 2025
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2564612 mar 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware12 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware12 mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
MS17-010 (CVE-2017-0143) - Python3 Script
CVE-2017-0143HIGHbajo ataqueransomware12 mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
GLPI Inventory Plugin Unauthenticated Blind Boolean SQLi
CVE-2025-24799HIGH12 mar 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
GitHub PoC
PoC Exploit for CVE-2015-0009 (SMB Signing)
CVE-2015-000912 mar 2025
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RIESGO
abrir
GitHub PoC1
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
CVE-2025-28915CRITICAL12 mar 2025
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC7
tinashelorenzi/CVE-2023-30258-magnus-billing-v7-exploit
CVE-2023-30258CRITICAL12 mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-0143HIGHbajo ataqueransomware12 mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
CVE-2024-10924 - Authentication Bypass in ReallySimpleSSL Wordpress Plugin
CVE-2024-10924CRITICAL11 mar 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
CVE-2017-11882 Preventer for .docx files
CVE-2017-11882HIGHbajo ataqueransomware11 mar 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
anteriorpágina 296 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.