Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
76.107 exploits
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHbajo ataque30 ene 2025
Openfire administration console authentication bypass
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 ene 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RIESGO
abrir
GitHub PoC
lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
CVE-2021-2301730 ene 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHbajo ataque30 ene 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC50
An XNU kernel race condition bug
CVE-2025-24118CRITICAL30 ene 2025
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS S
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware30 ene 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC4
honeyb33z/cve-2020-11023-scanner
CVE-2020-11023MEDIUMbajo ataque30 ene 2025
Potential XSS vulnerability in jQuery
85RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware30 ene 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-33891HIGHbajo ataque30 ene 2025
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2022-33891
CVE-2022-33891HIGHbajo ataque30 ene 2025
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 ene 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RIESGO
abrir
GitHub PoC15
CVE-2024-8381: A SpiderMonkey Interpreter Type Confusion Bug.
CVE-2024-8381CRITICAL30 ene 2025
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
48RIESGO
abrir
GitHub PoC1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALbajo ataqueransomware30 ene 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
asepsaepdin/CVE-2022-36804
CVE-2022-36804HIGHbajo ataque30 ene 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Metasploit300
NetAlertX File Read Vulnerability
CVE-2024-48766HIGH30 ene 2025
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RIESGO
abrir
Metasploit600
Unauthenticated RCE in NetAlertX
CVE-2024-46506CRITICAL30 ene 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALbajo ataqueransomware29 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL29 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALbajo ataqueransomware29 ene 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALbajo ataqueransomware29 ene 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALbajo ataqueransomware29 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware29 ene 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 ene 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
GitHub PoC1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 ene 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RIESGO
abrir
GitHub PoC11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALbajo ataqueransomware29 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALbajo ataqueransomware28 ene 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC3
watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248
CVE-2024-48248HIGHbajo ataque28 ene 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-48248HIGHbajo ataque28 ene 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-2961HIGH27 ene 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALbajo ataqueransomware27 ene 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
anteriorpágina 308 / 2537siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.