Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.041exploits catalogados
32.227CVEs con explotación pública
1932probados en laboratorio
72.258 exploits
VulnCheck XDB
initial-access
CVE-2025-47916CRITICAL21 nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
GitHub PoC1
Adel-kaka-dz/cve-2025-59287
CVE-2025-59287CRITICALbajo ataque21 nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Fully automated Confluence RCE exploit (CVE-2023-22527 + OGNL injection) 100% from scratch • Python • 2025
CVE-2023-22527CRITICALbajo ataqueransomware21 nov 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RIESGO
abrir
GitHub PoC1
Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated SSRF or local file access.
CVE-2024-58258HIGH21 nov 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir
GitHub PoC1
Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)
CVE-2025-64446CRITICALbajo ataque21 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC1
Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template processing in the "customCss()" method.
CVE-2025-47916CRITICAL21 nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
GitHub PoC4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
CVE-2025-61757CRITICALbajo ataque21 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir
GitHub PoC
On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability. The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .
CVE-2024-21413CRITICALbajo ataque20 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework
CVE-2022-22965CRITICALbajo ataque20 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
anelya0333/Exploiting-CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware20 nov 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
CVE-2025-13390CRITICAL20 nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RIESGO
abrir
GitHub PoC
lastvocher/7zip-CVE-2025-11001
CVE-2025-11001HIGH20 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque20 nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware20 nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-11001HIGH20 nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque20 nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735CRITICAL20 nov 2025
CVE-2025-12735
48RIESGO
abrir
GitHub PoC
thepiyushkumarshukla/CVE-2022-24707_AnukoTimeTracker_Version-1.20.0_POC
CVE-2022-24707HIGH20 nov 2025
SQL injection in anuko timetracker
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13390CRITICAL20 nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-61757CRITICALbajo ataque20 nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RIESGO
abrir
GitHub PoC
Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action
CVE-2025-13374CRITICAL20 nov 2025
Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action
48RIESGO
abrir
GitHub PoC3
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.
CVE-2025-3248CRITICALbajo ataqueransomware20 nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC4
MonstaFTP Unauthenticated File Upload
CVE-2025-34299CRITICAL19 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHbajo ataqueransomware19 nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALbajo ataqueransomware19 nov 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL19 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-58034MEDIUMbajo ataque19 nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir
GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHbajo ataqueransomware19 nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Loaxert/CVE-2018-15133-PoC
CVE-2018-15133HIGHbajo ataque19 nov 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC1
A comprehensive Python-based vulnerability scanner for detecting CVE-2021-41773 and CVE-2021-42013 path traversal and remote code execution vulnerabilities in Apache HTTP Server versions 2.4.49 and 2.4.50.
CVE-2021-42013CRITICALbajo ataqueransomware19 nov 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
anteriorpágina 173 / 2409siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.