Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
75.902 exploits
GitHub PoC
MandipJoshi/CVE-2021-3560
CVE-2021-3560HIGHbajo ataque13 may 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL13 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL13 may 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
CVE-2025-3248CRITICALbajo ataqueransomware13 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
Exploit-DB
TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
CVE-2024-11237HIGHlocalmultiple13 may 2025
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-24085CRITICALbajo ataque13 may 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RIESGO
abrir
Exploit-DB
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
CVE-2025-3605CRITICALwebappsmultiple13 may 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
GitHub PoC3
rebelle3/cve-2017-7117
CVE-2017-711712 may 2025
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir
GitHub PoC
shishirpandey18/CVE-2021-3156
CVE-2021-3156HIGHbajo ataque12 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque12 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2025-4603CRITICAL12 may 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware12 may 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC55
WHW0x455/CVE-2023-41992
CVE-2023-41992HIGHbajo ataque12 may 2025
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RIESGO
abrir
GitHub PoC
使用PowsrShell掃描CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware12 may 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
CVE-2023-37582CRITICAL12 may 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir
GitHub PoC1
fatkz/CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque11 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
PolarisXSec/CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque11 may 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Windows & linux support
CVE-2023-42793CRITICALbajo ataqueransomware11 may 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware11 may 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-0411HIGHbajo ataque11 may 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque11 may 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque11 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass
CVE-2025-0411HIGHbajo ataque11 may 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
GitHub PoC1
Apache CXF SSRF CVE-2024-28752
CVE-2024-28752CRITICAL10 may 2025
Apache CXF SSRF Vulnerability using the Aegis databinding
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque10 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL10 may 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC2
WordPress PDF 2 Post Plugin <= 2.4.0 is vulnerable to Remote Code Execution (RCE) +Subscriber
CVE-2025-32583CRITICAL10 may 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RIESGO
abrir
GitHub PoC
congdong007/CVE-2025-29306_poc
CVE-2025-29306CRITICAL10 may 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RIESGO
abrir
GitHub PoC3
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
CVE-2025-4403CRITICAL10 may 2025
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
48RIESGO
abrir
GitHub PoC
PoC for CVE-2017-5487 - WordPress User Enumeration via REST
CVE-2017-548710 may 2025
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
anteriorpágina 261 / 2531siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.