Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Exploit-DB
Adobe ColdFusion 2023.6 - Remote File Read
CVE-2024-20767HIGHbajo ataquewebappsmultiple28 jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 6
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
CVE-2025-24813CRITICALbajo ataque28 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC
imbas007/CVE-2025-32429-Checker
CVE-2025-32429CRITICAL28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗
GitHub PoC★ 1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462LOW28 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir ↗
GitHub PoC★ 3
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RIESGO
abrir ↗
GitHub PoC
Tools for detecting and assessing systems vulnerable to CVE-2025-53770 (CWE-502: Deserialization of Untrusted Data).
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗
Exploit-DB
Xlight FTP 1.1 - Denial Of Service (DOS)
CVE-2024-0737MEDIUMdosmultiple28 jul 2025
Xlightftpd Xlight FTP Server Login denial of service
33RIESGO
abrir ↗
GitHub PoC★ 2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
CVE-2025-8191MEDIUM28 jul 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque28 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL28 jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir ↗
GitHub PoC
Threat-Informed Detection & Mitigation Package for MOVEit Transfer Vulnerability
CVE-2023-34362CRITICALbajo ataqueransomware28 jul 2025
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
Exploit-DB
XWiki 14 - SQL Injection via getdeleteddocuments.vm
CVE-2025-32429CRITICALwebappsmultiple28 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware28 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque27 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
An activity to train analysis skills and reporting
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 2
r0otk3r/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque27 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗
GitHub PoC★ 15
CVE-2025-53770 Mass Scanner
CVE-2025-53770CRITICALbajo ataqueransomware27 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗
GitHub PoC
QHxDr-dz/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware27 jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗
GitHub PoC
The POC for m6.fr website
CVE-2025-29927CRITICAL27 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗
GitHub PoC
Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only
CVE-2025-32429CRITICAL26 jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗
GitHub PoC
Checks projects for compromised packages, suspicious files, and import statements.
CVE-2025-54313HIGHbajo ataque26 jul 2025
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque26 jul 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
← anteriorpágina 301 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.