Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 sep 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALbajo ataqueransomware16 sep 2025
Authentication bypass using an alternate path or channel
100RIESGO
abrir
GitHub PoC2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALbajo ataque16 sep 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque16 sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALbajo ataque16 sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-24799HIGH16 sep 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
CVE-2021-43579remotemultiple16 sep 2025
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-1708HIGHbajo ataqueransomware16 sep 2025
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1261115 sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir
GitHub PoC
Authentication bypass vulnerability in versions of the CrushFTP server.
CVE-2025-31161CRITICALbajo ataqueransomware15 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware15 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
CVE-2024-28397MEDIUM15 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC2
Langflow Remote Code Execution
CVE-2025-3248CRITICALbajo ataqueransomware15 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-9822HIGHbajo ataqueransomware15 sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
GitHub PoC
tcetin704/CVE-2017-12611
CVE-2017-1261115 sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir
GitHub PoC
tranphuc2005/CVE-2017-9822
CVE-2017-9822HIGHbajo ataqueransomware15 sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir
GitHub PoC
Shubhankargupta691/CVE-2024-42009
CVE-2024-42009CRITICALbajo ataque14 sep 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
GitHub PoC
A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution.
CVE-2025-8088HIGHbajo ataque14 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to 2.4.51+, CGI disable, firewall) and published the analysis on GitHub.
CVE-2021-41773HIGHbajo ataqueransomware14 sep 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
CVE-2025-57819CRITICALbajo ataque14 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque14 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
local
CVE-2025-48543HIGHbajo ataque14 sep 2025
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft
71RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALbajo ataque14 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3_2_1_fixed
CVE-2023-49109CRITICAL14 sep 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir
GitHub PoC
CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque13 sep 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
Metasploit600
Flowise JS Injection RCE
CVE-2025-59528CRITICAL13 sep 2025
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL13 sep 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
CVE-2024-9264CRITICAL13 sep 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir
GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CVE-2025-54309CRITICALbajo ataque13 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque13 sep 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
anteriorpágina 199 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.