Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
13.282 exploits
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
CVE-2023-49109CRITICAL19 ago 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir
GitHub PoC
CVE-2025-8088
CVE-2025-8088HIGHbajo ataque19 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC8
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution
CVE-2025-8723CRITICAL19 ago 2025
Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
53RIESGO
abrir
GitHub PoC
This is a rewritten exploit to work with php
CVE-2025-49113CRITICALbajo ataque19 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
CVE-2025-29927CRITICAL19 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
GitHub PoC1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
CVE-2025-49113CRITICALbajo ataque18 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 ago 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir
GitHub PoC1
harutomo-jp/CVE-2024-28397-RCE
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
chan-068/CVE-2024-0520_try
CVE-2024-0520CRITICAL18 ago 2025
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RIESGO
abrir
GitHub PoC
CVE-2015-6967 PoC Exploit
CVE-2015-696718 ago 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
GitHub PoC5
CVE PoC
CVE-2013-3900MEDIUMbajo ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
CVE-2022-3782CRITICAL18 ago 2025
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RIESGO
abrir
GitHub PoC2
Proof of concept for CVE-2020-36708
CVE-2020-36708CRITICAL18 ago 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir
GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
CVE-2015-10141CRITICAL17 ago 2025
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RIESGO
abrir
GitHub PoC2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
CVE-2025-8088HIGHbajo ataque17 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
CVE-2020-5410HIGHbajo ataque17 ago 2025
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir
GitHub PoC3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALbajo ataque17 ago 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC
Demo of CVE-2025-29927 for secure programming class
CVE-2025-29927CRITICAL17 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC21
Detection for CVE-2025-8875 & CVE-2025-8876
CVE-2025-8875CRITICALbajo ataque17 ago 2025
Insecure Deserialization Vulnerability
78RIESGO
abrir
GitHub PoC5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
CVE-2024-28397MEDIUM17 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CVE-2011-273217 ago 2025
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RIESGO
abrir
GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
CVE-2019-1218517 ago 2025
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RIESGO
abrir
GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
CVE-2023-37908CRITICAL16 ago 2025
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RIESGO
abrir
GitHub PoC
Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version 1.890 (CVE-2019-15107), ultimately gaining full control over the target system.
CVE-2019-15107CRITICALbajo ataqueransomware16 ago 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
CVE-2023-37582CRITICAL16 ago 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
CVE-2025-8088HIGHbajo ataque16 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
anteriorpágina 124 / 443siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.