Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
75.589 exploits
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque19 jun 2025
Incorrect Authorization in Graphics
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41352CRITICALbajo ataque19 jun 2025
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir
GitHub PoC
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
CVE-2019-11043HIGHbajo ataqueransomware19 jun 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC1
CVE-2025-3248 — Langflow RCE Exploit
CVE-2025-3248CRITICALbajo ataqueransomware19 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
CVE-2007-244719 jun 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
This is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157819 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-1094HIGH18 jun 2025
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque18 jun 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC1
CVE-2025-33053 Checker and PoC
CVE-2025-33053HIGHbajo ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
punitdarji/roundcube-cve-2025-49113
CVE-2025-49113CRITICALbajo ataque18 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC2
imbas007/CVE-2025-3248
CVE-2025-3248CRITICALbajo ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC3
Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF payload and a video-only showcase of potential command-and-control capabilities.
CVE-2025-33053HIGHbajo ataque18 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Exploit for Langflow AI Remote Code Execution (Unauthenticated)
CVE-2025-3248CRITICALbajo ataqueransomware18 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation with Metasploit, post-exploitation, and remediation steps in a controlled lab environment.
CVE-2017-0143HIGHbajo ataqueransomware17 jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC17
CVE-2025-3248 Langflow RCE Exploit
CVE-2025-3248CRITICALbajo ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
Explicação + Lab no THM
CVE-2025-49113CRITICALbajo ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
Kernel Pool Overflow Exploit targeting CVE-2021-31956
CVE-2021-31956HIGHbajo ataque17 jun 2025
Windows NTFS Elevation of Privilege Vulnerability
76RIESGO
abrir
Metasploit600
Sitecore XP CVE-2025-34511 Post-Authentication File Upload
CVE-2025-34511HIGH17 jun 2025
Sitecore PowerShell Extension RCE via Unrestricted Upload
41RIESGO
abrir
Metasploit600
Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution
CVE-2025-34510HIGH17 jun 2025
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
41RIESGO
abrir
GitHub PoC
EdouardosStav/CVE-2019-15107-RCE-WebMin
CVE-2019-15107CRITICALbajo ataqueransomware17 jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH17 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware17 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque17 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALbajo ataque16 jun 2025
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH16 jun 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RIESGO
abrir
GitHub PoC
A Python-based Exploit Script for CVE-2016-3088
CVE-2016-3088CRITICALbajo ataque16 jun 2025
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Exploit-DB
Parrot and DJI variants Drone OSes - Kernel Panic Exploit
CVE-2025-37928localmultiple15 jun 2025
dm-bufio: don't schedule in atomic context
23RIESGO
abrir
anteriorpágina 246 / 2520siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.