Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
75.526 exploits
Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
CVE-2025-49744HIGHlocalwindows16 jul 2025
Windows Graphics Component Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
CVE-2025-3248CRITICALbajo ataqueransomwarewebappsmultiple16 jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
Exploit-DB
TOTOLINK N300RB 8.54 - Command Execution
CVE-2025-52089HIGHhardwaremultiple16 jul 2025
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti
41RIESGO
abrir
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALbajo ataqueransomware16 jul 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
CVE-2024-11605MEDIUMwebappsmultiple16 jul 2025
WP Publications <= 1.2 - Admin+ Stored XSS
33RIESGO
abrir
Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
CVE-2024-58258HIGHwebappsmultiple16 jul 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir
Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
CVE-2025-49677HIGHlocalwindows16 jul 2025
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
MikroTik RouterOS 7.19.1 - Reflected XSS
CVE-2025-6563MEDIUMremotemultiple16 jul 2025
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
33RIESGO
abrir
Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
CVE-2025-34300CRITICAL16 jul 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir
GitHub PoC
malaya-m/cve-2013-3900-remediation-report
CVE-2013-3900MEDIUMbajo ataque16 jul 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC
Floodnut/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque16 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC2
joelczk/CVE-2025-52688
CVE-2025-52688CRITICAL16 jul 2025
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware16 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1261315 jul 2025
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
ECHO6789/CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque15 jul 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
CVE-2025-25257CRITICALbajo ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque15 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
CVE-2025-5777 (CitrixBleed 2) - [Citrix NetScaler ADC] [Citrix Gateway]
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC3
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but also helps in demonstrating its impact by parsing human-readable information from the memory leak.
CVE-2025-5777CRITICALbajo ataqueransomware15 jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque15 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALbajo ataque14 jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC2
This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
CVE-2025-41656CRITICAL14 jul 2025
Pilz: Missing Authentication in Node-RED integration
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-536014 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-7340CRITICAL14 jul 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL14 jul 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
GitHub PoC2
Royal Elementor Addons - Unauthenticated Remote Code Execution
CVE-2023-536014 jul 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-52488HIGH14 jul 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
68RIESGO
abrir
anteriorpágina 229 / 2518siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.