Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.444exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.444 exploits
VulnCheck XDB
initial-access
CVE-2017-1254213 oct 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
GitHub PoC
This script checks if an HP iLO server is vulnerable and can add an admin user
CVE-2017-1254213 oct 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
GitHub PoC
laachy/CVE-2024-39930-ptrace-detection-mitigation
CVE-2024-39930CRITICAL13 oct 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RIESGO
abrir
GitHub PoC
Scottman625/CVE-2023-29360
CVE-2023-29360HIGHbajo ataque12 oct 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
local
CVE-2023-29360HIGHbajo ataque12 oct 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 oct 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC1
PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"
CVE-2024-27304CRITICAL12 oct 2025
pgx SQL Injection via Protocol Message Size Overflow
48RIESGO
abrir
GitHub PoC
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
CVE-2017-594112 oct 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 oct 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-11371HIGHbajo ataque11 oct 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-46982HIGH11 oct 2025
Cache Poisoning in next.js
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque10 oct 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC3
CVE-2024-38856: Apache OFBiz remote code execution Scanner & Exploit
CVE-2024-38856HIGHbajo ataque10 oct 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-61882CRITICALbajo ataqueransomware10 oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH10 oct 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL10 oct 2025
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque09 oct 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALbajo ataque09 oct 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
GitHub PoC
CVE-2024-32113-Apache-OFBiz<18.12.13-Exploit
CVE-2024-32113CRITICALbajo ataque09 oct 2025
Apache OFBiz: Path traversal leading to RCE
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL09 oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware09 oct 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC2
CVE-2023-21554 PoC
CVE-2023-21554CRITICAL09 oct 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC
syorik/CVE-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware09 oct 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
foregenix/CVE-2023-39143
CVE-2023-39143CRITICAL09 oct 2025
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RIESGO
abrir
Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
CVE-2025-52691CRITICALbajo ataqueransomware09 oct 2025
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC
lastvocher/Hikvision-CVE-2017-7921-decryptor
CVE-2017-7921CRITICALbajo ataque08 oct 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 oct 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-10353CRITICAL08 oct 2025
Missing Authorization vulnerability in Melis Platform
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-7441CRITICAL07 oct 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL07 oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
anteriorpágina 192 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.