Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
GitHub PoC1
A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters via GraphQL mutations, and how to detect, analyze, and report the breach using ELK.
CVE-2025-59359CRITICAL18 sep 2025
OS command injection in Chaos Mesh via the cleanTcs mutation
48RIESGO
abrir
GitHub PoC
WinRAR漏洞CVE-2025-8088的payload一键生成工具
CVE-2025-8088HIGHbajo ataque18 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
There are Exploit for Magnus Billing v7 system get root privilages
CVE-2023-30258CRITICAL18 sep 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL18 sep 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque18 sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
PoC for achieving RCE in Langflow versions <1.3.0
CVE-2025-3248CRITICALbajo ataqueransomware17 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22600MEDIUMbajo ataque17 sep 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RIESGO
abrir
GitHub PoC
do not use. vulnerable
CVE-2025-29927CRITICAL17 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
CVE-2024-28397 - Remote Code Execution From Vulnerable JS2PY
CVE-2024-28397MEDIUM17 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve remote code execution.
CVE-2024-28397MEDIUM17 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL17 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHbajo ataque17 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
CVE-2010-124017 sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir
GitHub PoC1
Proof-Of-Concept to check privileges of af_packet.c for validating the privileges acquired by any hacker upon successful exploitation of CVE-2021-22600
CVE-2021-22600MEDIUMbajo ataque17 sep 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware17 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2010-124017 sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir
Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
CVE-2025-8311CRITICALwebappsmultiple16 sep 2025
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RIESGO
abrir
Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
CVE-2025-8573LOWwebappsmultiple16 sep 2025
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-24799HIGH16 sep 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
CVE-2025-47917HIGHlocalmultiple16 sep 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RIESGO
abrir
GitHub PoC
PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability
CVE-2025-20265CRITICAL16 sep 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RIESGO
abrir
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
CVE-2021-43579remotemultiple16 sep 2025
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RIESGO
abrir
Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
CVE-2023-44487HIGHbajo ataqueremotemultiple16 sep 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALbajo ataqueransomware16 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 sep 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RIESGO
abrir
GitHub PoC2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALbajo ataque16 sep 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware16 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALbajo ataque16 sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC2
Example PoC for CVE-2025-24813 (Tomcat RCE)
CVE-2025-24813CRITICALbajo ataque16 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple16 sep 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RIESGO
abrir
anteriorpágina 198 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.