Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
VulnCheck XDB
info-leak
CVE-2019-9978MEDIUMbajo ataque01 ene 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque01 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware01 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-30208MEDIUM01 ene 2026
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-0288HIGH01 ene 2026
CVE-2025-0288
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque01 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook
CVE-2024-21413CRITICALbajo ataque01 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
MongoBleed CVE-2025-14847 Vulnerability Checker
CVE-2025-14847HIGHbajo ataque01 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
CVE-2025-52691
CVE-2025-52691CRITICALbajo ataqueransomware01 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC
galois17/cve-2017-12149-playground
CVE-2017-12149CRITICALbajo ataqueransomware01 ene 2026
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC3
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
CVE-2025-54068CRITICALbajo ataque01 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC1
A new way to exploit CVE-2025-58360 bypass WAF
CVE-2025-58360HIGHbajo ataque31 dic 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
CVE-2025-14847HIGHbajo ataque31 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
CVE-2014-370431 dic 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
CVE-2025-55182CRITICALbajo ataqueransomware31 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
nkuty/CVE-2025-54322-exploit
CVE-2025-54322CRITICAL31 dic 2025
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2018-1171431 dic 2025
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALbajo ataqueransomware31 dic 2025
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC5
Poc for CVE-2025-7771 to modify PPL Protection
CVE-2025-7771HIGH31 dic 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH31 dic 2025
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
GitHub PoC
YanC1e/CVE-2025-8191
CVE-2025-8191MEDIUM30 dic 2025
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALbajo ataqueransomware30 dic 2025
Upload Arbitrary Files
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque30 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
CVE-2025-55182CRITICALbajo ataqueransomware30 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
CVE-2020-0796CRITICALbajo ataqueransomware30 dic 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-14847HIGHbajo ataque30 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque30 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque30 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque30 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware30 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 213 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.