Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
Exploit-DB
RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
CVE-2020-15718webappsphp03 dic 2025
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc
38RIESGO
abrir
Exploit-DB
Django 5.1.13 - SQL Injection
CVE-2025-64459CRITICALwebappsmultiple03 dic 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque03 dic 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALbajo ataqueransomware03 dic 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
GitHub PoC792
CVE-2025-55182 POC
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
phpMyAdmin 5.0.0 - SQL Injection
CVE-2020-5504webappsphp03 dic 2025
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RIESGO
abrir
Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
CVE-2017-15808webappsphp03 dic 2025
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
CVE-2017-15734webappsphp03 dic 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RIESGO
abrir
Exploit-DB
phpIPAM 1.4 - SQL-Injection
CVE-2019-16693webappsphp03 dic 2025
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
23RIESGO
abrir
GitHub PoC
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
openSIS Community Edition 8.0 - SQL Injection
CVE-2021-40617webappsphp03 dic 2025
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
23RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-6647803 dic 2025
15RIESGO
abrir
Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
CVE-2017-6478webappsmultiple03 dic 2025
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC4
santihabib/CVE-2025-55182-analysis
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
CVE-2018-25080LOWwebappsphp03 dic 2025
MobileDetect Example session_example.php initLayoutType cross site scripting
28RIESGO
abrir
Exploit-DB
OpenRepeater 2.1 - OS Command Injection
CVE-2019-25024webappsphp03 dic 2025
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RIESGO
abrir
GitHub PoC
Vulnerable environment for testing CVE-2021-22941 Nuclei template
CVE-2021-22941CRITICALbajo ataqueransomware02 dic 2025
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RIESGO
abrir
GitHub PoC
boro03/CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware02 dic 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
CVE-2025-13486CRITICAL02 dic 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
75RIESGO
abrir
GitHub PoC1
Jorge2Rubio/CVE-2019-0232
CVE-2019-023202 dic 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
sudlit/CVE-2017-7494
CVE-2017-7494CRITICALbajo ataqueransomware02 dic 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC1
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
CVE-2025-29927CRITICAL02 dic 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
CVE-2021-21551HIGHbajo ataque02 dic 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL02 dic 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware02 dic 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
towaos/towaos-lab-cve-2020-11023
CVE-2020-11023MEDIUMbajo ataque02 dic 2025
Potential XSS vulnerability in jQuery
85RIESGO
abrir
Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-0088LOWwebappsmultiple02 dic 2025
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RIESGO
abrir
Exploit-DB
Piwigo 13.6.0 - SQL Injection
CVE-2023-33362CRITICALwebappsphp02 dic 2025
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RIESGO
abrir
Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
CVE-2024-41357HIGHwebappsphp02 dic 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RIESGO
abrir
anteriorpágina 247 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.