Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
81.521 exploits
VulnCheck XDB
client-side
CVE-2023-38408CRITICAL19 abr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗
GitHub PoC★ 1
cybermads/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗
GitHub PoC★ 3
Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.
CVE-2022-0847HIGHbajo ataque19 abr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
GitHub PoC
Go-based exploit for CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC
pruthuraut/CVE-2025-28121
CVE-2025-28121MEDIUM19 abr 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p
33RIESGO
abrir ↗
Exploit-DB
FoxCMS 1.2.5 - Remote Code Execution (RCE)
CVE-2025-29306CRITICALwebappsmultiple19 abr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque19 abr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
GitHub PoC★ 6
0xPThree/cve-2025-32433
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
GitHub PoC
JenmrR/Node.js-CVE-2024-39943
CVE-2024-39943CRITICAL19 abr 2025
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RIESGO
abrir ↗
GitHub PoC★ 7
CVE-2023-38408 SSH Vulnerability Scanner & PoC
CVE-2023-38408CRITICAL19 abr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALbajo ataqueransomware19 abr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque19 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-8425CRITICAL19 abr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗
GitHub PoC
PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)
CVE-2024-4577CRITICALbajo ataqueransomware18 abr 2025
Argument Injection in PHP-CGI
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-21756HIGH18 abr 2025
vsock: Keep the binding until socket destruction
41RIESGO
abrir ↗
Exploit-DB
Inventio Lite 4 - SQL Injection
CVE-2024-44541CRITICALwebappsphp18 abr 2025
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
Exploit-DB
Langflow 1.3.0 - Remote Code Execution (RCE)
CVE-2025-3248CRITICALbajo ataqueransomwareremotemultiple18 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24054MEDIUMbajo ataque18 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗
Exploit-DB
Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICALwebappsmultiple18 abr 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque18 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC★ 4
PoC - CVE-2025-24071 / CVE-2025-24054, NTMLv2 hash'leri alınabilen bir vulnerability
CVE-2025-24054MEDIUMbajo ataque18 abr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware18 abr 2025
Argument Injection in PHP-CGI
100RIESGO
abrir ↗
Exploit-DB
UJCMS 9.6.3 - User Enumeration via IDOR
CVE-2024-12483MEDIUMwebappsmultiple18 abr 2025
Dromara UJCMS User ID id authorization
33RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM18 abr 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗
← anteriorpágina 347 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.