Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2018-12613—15 jul 2025
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir ↗
GitHub PoC
ECHO6789/CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque15 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
GitHub PoC★ 1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
CVE-2025-25257CRITICALbajo ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque15 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC★ 7
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir ↗
GitHub PoC
Armand2002/Exploit-CVE-2025-1974-Lab
CVE-2025-1974CRITICAL14 jul 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-5360—14 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
GitHub PoC
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC★ 2
This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
CVE-2025-41656CRITICAL14 jul 2025
Pilz: Missing Authentication in Node-RED integration
53RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL14 jul 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC★ 48
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALbajo ataque14 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC★ 1
This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin 5.0.0–5.7.5 and 6.0.0–6.0.3 when running on PHP 8.1 or later. The vulnerability allows unauthenticated attackers to invoke protected API methods remotely.
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir ↗
GitHub PoC
mheranco/CVE-2025-44136
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-52488HIGH14 jul 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
68RIESGO
abrir ↗
GitHub PoC★ 2
Royal Elementor Addons - Unauthenticated Remote Code Execution
CVE-2023-5360—14 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM14 jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-44136CRITICAL14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e
63RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-44137HIGH14 jul 2025
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp
56RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque14 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-34085—13 jul 2025
20RIESGO
abrir ↗
GitHub PoC
CVE-2025-32023
CVE-2025-32023HIGH13 jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RIESGO
abrir ↗
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMbajo ataque13 jul 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALbajo ataque13 jul 2025
Remote code execution in Wazuh server
100RIESGO
abrir ↗
GitHub PoC★ 8
Wazuh 8.4 CVE-2025-24016
CVE-2025-24016CRITICALbajo ataque13 jul 2025
Remote code execution in Wazuh server
100RIESGO
abrir ↗
← anteriorpágina 311 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.