Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
VulnCheck XDB
local
CVE-2023-32434HIGHbajo ataque01 mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RIESGO
abrir
GitHub PoC
CVE-2019-18935: Remote Code Execution
CVE-2019-18935CRITICALbajo ataqueransomware01 mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC1
overgrowncarrot1/CVE-2019-1003030
CVE-2019-1003030CRITICALbajo ataque01 mar 2025
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
GitHub PoC129
Deterministic kernel exploit based on CVE-2023-32434.
CVE-2023-32434HIGHbajo ataque01 mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RIESGO
abrir
GitHub PoC
CVE-2023-1545-POC with python
CVE-2023-1545HIGH01 mar 2025
SQL Injection in nilsteampassnet/teampass
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware01 mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC4
Mautic < 5.2.3 Authenticated RCE
CVE-2024-47051CRITICAL28 feb 2025
Remote Code Execution & File Deletion in Asset Uploads
48RIESGO
abrir
GitHub PoC1
skrkcb2/CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware27 feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC233
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
CVE-2025-21333HIGHbajo ataque27 feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware27 feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-21333HIGHbajo ataque27 feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware26 feb 2025
Information disclosure
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-24752HIGH26 feb 2025
WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALbajo ataqueransomware26 feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware26 feb 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque26 feb 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26263MEDIUM26 feb 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RIESGO
abrir
GitHub PoC
Automation script to exploit the Shellshock vulnerability.
CVE-2014-6271CRITICALbajo ataque26 feb 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
SpiX-7/CVE-2024-24919-POC
CVE-2024-24919HIGHbajo ataqueransomware26 feb 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
cojoben/CVE-2018-13382
CVE-2018-13382CRITICALbajo ataqueransomware26 feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
GitHub PoC
monjheta/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware26 feb 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC7
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264HIGH26 feb 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque25 feb 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
CVE-2025-24893CRITICALbajo ataque25 feb 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMbajo ataque25 feb 2025
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-0282CRITICALbajo ataqueransomware25 feb 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL25 feb 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RIESGO
abrir
GitHub PoC21
JSONPath-plus Remote Code Execution
CVE-2025-1302CRITICAL25 feb 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque25 feb 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-1302CRITICAL25 feb 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RIESGO
abrir
anteriorpágina 299 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.