Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
GitHub PoC★ 2
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
CVE-2024-43425HIGH13 jul 2025
Moodle: remote code execution via calculated question types
78RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2015-8562—13 jul 2025
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗
GitHub PoC
This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).
CVE-2017-0143HIGHbajo ataqueransomware13 jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗
GitHub PoC★ 8
Wazuh 8.4 CVE-2025-24016
CVE-2025-24016CRITICALbajo ataque13 jul 2025
Remote code execution in Wazuh server
100RIESGO
abrir ↗
GitHub PoC
JayVillain/Scan-CVE-2025-6058
CVE-2025-6058CRITICAL13 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-22457CRITICALbajo ataqueransomware13 jul 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗
GitHub PoC
CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This lab is built for CTF players and bug bounty learners to simulate real-world exploitation workflows including token extraction, password reset, and flag capture.
CVE-2020-35848—13 jul 2025
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-34085—13 jul 2025
20RIESGO
abrir ↗
GitHub PoC
r0otk3r/CVE-2024-1212
CVE-2024-1212CRITICALbajo ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir ↗
GitHub PoC
pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck-
CVE-2013-3900MEDIUMbajo ataque12 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗
GitHub PoC
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2025-6058CRITICAL12 jul 2025
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗
GitHub PoC★ 1
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523—12 jul 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗
GitHub PoC★ 1
Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.
CVE-2025-24813CRITICALbajo ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque12 jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
GitHub PoC★ 1
imbas007/CVE-2025-25257
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
GitHub PoC
r0otk3r/CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗
GitHub PoC
MacUchegit/Detecting-and-Analyzing-CVE-2024-24919-Exploitation
CVE-2024-24919HIGHbajo ataqueransomware12 jul 2025
Information disclosure
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
GitHub PoC
Tool for detecting and exploiting CVE-2025-25257 in Fortinet FortiWeb.
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware12 jul 2025
Information disclosure
100RIESGO
abrir ↗
GitHub PoC★ 1
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
CVE-2025-25257CRITICALbajo ataque12 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 jul 2025
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1212CRITICALbajo ataque12 jul 2025
LoadMaster Pre-Authenticated OS Command Injection
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque11 jul 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque11 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RIESGO
abrir ↗
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALbajo ataque11 jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
GitHub PoC
hackmelocal/CVE-2025-49113-Simulation
CVE-2025-49113CRITICALbajo ataque11 jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
← anteriorpágina 312 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.