Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
72.018 exploits
Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
CVE-2024-41357HIGH02 dic 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RIESGO
abrir
GitHub PoC
letsr00t/CVE-2013-2094
CVE-2013-2094HIGHbajo ataque01 dic 2025
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
GitHub PoC2
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)
CVE-2025-64459CRITICAL01 dic 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-919301 dic 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC8
Reverse engineering research and custom firmware for the Allwinner V3-based SJCAM SJ4000 Air, including firmware parsers, an AVIOCTRL client, security research, and the CVE-2026-52656 proof of concept.
CVE-2026-52656CRITICAL01 dic 2025
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL01 dic 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66294HIGH01 dic 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66301HIGH01 dic 2025
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RIESGO
abrir
Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
CVE-2025-12548CRITICAL01 dic 2025
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-2198001 dic 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21413CRITICALbajo ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-3581330 nov 2025
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL30 nov 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
GitHub PoC11
Outlook exploitation
CVE-2024-21413CRITICALbajo ataque30 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
m2hcz/CVE-2025-6440-Poc-Exploit
CVE-2025-6440CRITICAL29 nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
CVE-2025-8088HIGHbajo ataque29 nov 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
KylVGoi/cve-2019-1663
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2018-10933 - LibSSH - Authentication Bypass
CVE-2018-10933CRITICAL29 nov 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
sec-dojo-com/CVE-2020-24186
CVE-2020-24186CRITICAL29 nov 2025
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1663CRITICAL29 nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13315CRITICAL28 nov 2025
Unauthenticated log access in Twonky Server
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
Modified the CVE-2024-25600
CVE-2024-25600CRITICAL28 nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2010-2075
CVE-2010-207528 nov 2025
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC
Exploit - CVE-2023-26360
CVE-2023-26360HIGHbajo ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
GitHub PoC
AndrewMas99/CVE-2019-11043-Vulnerability
CVE-2019-11043HIGHbajo ataqueransomware28 nov 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-2011HIGH28 nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-26360HIGHbajo ataque28 nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-2198027 nov 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque27 nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
anteriorpágina 169 / 2401siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.