Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
75.445 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware19 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataque19 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC1
This is a rewritten exploit to work with php
CVE-2025-49113CRITICALbajo ataque19 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
CVE-2023-49109CRITICAL19 ago 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57790HIGH19 ago 2025
Path Traversal Vulnerability
41RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57791MEDIUM19 ago 2025
Argument Injection Vulnerability in CommServe
33RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57788MEDIUM19 ago 2025
Unauthorized API Access Risk
28RIESGO
abrir
Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
CVE-2024-28623MEDIUMwebappsmultiple18 ago 2025
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RIESGO
abrir
GitHub PoC3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 ago 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir
GitHub PoC
chan-068/CVE-2024-0520_try
CVE-2024-0520CRITICAL18 ago 2025
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-36708CRITICAL18 ago 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass
CVE-2015-6830remotephp18 ago 2025
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo
23RIESGO
abrir
Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
CVE-2024-54761MEDIUMwebappsmultiple18 ago 2025
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir
Exploit-DB
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
CVE-2025-7766HIGHwebappsmultiple18 ago 2025
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RIESGO
abrir
GitHub PoC1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC
CVE-2015-6967 PoC Exploit
CVE-2015-696718 ago 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
CVE-2025-49113CRITICALbajo ataque18 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
Exploit-DB
Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
CVE-2025-50154MEDIUMremotewindows18 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
VulnCheck XDB
local
CVE-2025-7771HIGH18 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-873918 ago 2025
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir
GitHub PoC1
harutomo-jp/CVE-2024-28397-RCE
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC2
Proof of concept for CVE-2020-36708
CVE-2020-36708CRITICAL18 ago 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir
GitHub PoC3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RIESGO
abrir
GitHub PoC5
CVE PoC
CVE-2013-3900MEDIUMbajo ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
CVE-2022-3782CRITICAL18 ago 2025
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RIESGO
abrir
Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
CVE-2025-9090MEDIUMremotemultiple18 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir
GitHub PoC1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALbajo ataque17 ago 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
GitHub PoC3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
anteriorpágina 210 / 2515siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.