Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
GitHub PoC
Sornphut/CVE-2023-7028-GitLab
CVE-2023-7028CRITICALbajo ataque29 mar 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
Exploit-DB
XWiki Standard 14.10 - Remote Code Execution (RCE)
CVE-2023-48292CRITICALwebappsphp29 mar 2025
XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
53RIESGO
abrir ↗
GitHub PoC★ 1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
CVE-2025-24071MEDIUM29 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM29 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir ↗
GitHub PoC★ 1
Here is a simple but effective exploit for CVE-2025-29927.
CVE-2025-29927CRITICAL29 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque29 mar 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir ↗
Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
CVE-2024-44000CRITICALwebappsphp28 mar 2025
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RIESGO
abrir ↗
GitHub PoC★ 91
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
Exploit-DB
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CVE-2024-4956HIGHwebappsmultiple28 mar 2025
Nexus Repository 3 - Path Traversal
61RIESGO
abrir ↗
GitHub PoC★ 3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2776CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2777CRITICAL28 mar 2025
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RIESGO
abrir ↗
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALbajo ataqueransomware28 mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-2775CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALbajo ataqueransomware28 mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
GitHub PoC★ 3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque28 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
Exploit-DB
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
CVE-2024-23692CRITICALbajo ataqueransomwarewebappstypescript28 mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir ↗
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
CVE-2024-4358CRITICALbajo ataquewebappsmultiple28 mar 2025
Registration Authentication Bypass Vulnerability
100RIESGO
abrir ↗
GitHub PoC★ 1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗
Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CVE-2024-8945MEDIUMwebappsphp28 mar 2025
CodeCanyon RISE Ultimate Project Manager save sql injection
38RIESGO
abrir ↗
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2025-30355HIGH28 mar 2025
Synapse vulnerable to federation denial of service via malformed events
41RIESGO
abrir ↗
GitHub PoC★ 12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALbajo ataque28 mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL28 mar 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗
← anteriorpágina 362 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.