Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
GitHub PoC9
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
CVE-2024-42327CRITICAL16 feb 2025
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
CVE-2019-1881816 feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
CVE-2023-3358016 feb 2025
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALbajo ataque16 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
CVE-2019-056715 feb 2025
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
CVE-2020-1938CRITICALbajo ataque15 feb 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
CVE-2024-10924CRITICAL14 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque14 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
php-cgi-cve-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Didarul342/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
CVE-2025-0108HIGHbajo ataque14 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
GitHub PoC
CVE-2016-6914-UniFiVideo-LPE
CVE-2016-691413 feb 2025
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RIESGO
abrir
GitHub PoC32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
CVE-2025-0108HIGHbajo ataque13 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALbajo ataque13 feb 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-0108HIGHbajo ataque13 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALbajo ataque13 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
CVE-2019-905313 feb 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC1
This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from a target webmail application. The attack injects a malicious payload that exfiltrates email content to an attacker-controlled listener.
CVE-2024-42009CRITICALbajo ataque13 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
GitHub PoC
Apache Struts CVE-2024-53677 Exploitation
CVE-2024-53677CRITICAL13 feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
luke0x90/CVE-2021-21551
CVE-2021-21551HIGHbajo ataque13 feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
CVE-2024-42008CRITICAL13 feb 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RIESGO
abrir
GitHub PoC4
huseyinstif/CVE-2025-24016-Nuclei-Template
CVE-2025-24016CRITICALbajo ataque13 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-24865CRITICAL13 feb 2025
mySCADA myPRO Manager Missing Authentication for Critical Function
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALbajo ataque13 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-22896CRITICAL13 feb 2025
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RIESGO
abrir
anteriorpágina 302 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.