Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
GitHub PoC
Optimized exploit for CVE-2021-43857 affecting Gerapy < 0.9.8
CVE-2021-43857CRITICAL24 abr 2025
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir ↗
GitHub PoC
unzip-stream file write/overwrite vulnerability
CVE-2024-42471HIGH24 abr 2025
Arbitrary File Write via artifact extraction in actions/artifact
41RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-34028CRITICALbajo ataque24 abr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL24 abr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque24 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
CVE-2018-15745—24 abr 2025
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque24 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM24 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
GitHub PoC★ 1
Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
GitHub PoC
CVE-2025-31161 python exploit
CVE-2025-31161CRITICALbajo ataqueransomware24 abr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque24 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2825—24 abr 2025
35RIESGO
abrir ↗
GitHub PoC
JIYUN02/cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware24 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2023-25157 exp
CVE-2023-25157CRITICAL24 abr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir ↗
GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
CVE-2025-34028CRITICALbajo ataque24 abr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir ↗
GitHub PoC★ 12
Exploit for CVE-2025-30406
CVE-2025-30406CRITICALbajo ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗
GitHub PoC
CVE lab to accompany CVE course for CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque24 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC★ 3
Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities
CVE-2025-30208MEDIUM24 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALbajo ataque24 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-7120MEDIUM24 abr 2025
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware24 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC
Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.
CVE-2024-49138HIGHbajo ataque23 abr 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir ↗
GitHub PoC★ 12
F5-Labs/parquet-canary-exploit-rce-poc-CVE-2025-30065
CVE-2025-30065CRITICAL23 abr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2020-10257CRITICAL23 abr 2025
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque23 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC★ 2
CVE-2025-29927: Next.js Middleware Bypass Vulnerability
CVE-2025-29927CRITICAL23 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24963MEDIUM23 abr 2025
Browser mode serves arbitrary files in vitest
48RIESGO
abrir ↗
GitHub PoC★ 22
Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071
CVE-2025-24054MEDIUMbajo ataque22 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗
← anteriorpágina 344 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.