Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL17 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2010-1240—17 sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware17 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
GitHub PoC
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
CVE-2010-1240—17 sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
GitHub PoC★ 1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHbajo ataqueransomware17 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC
do not use. vulnerable
CVE-2025-29927CRITICAL17 sep 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC
PoC for achieving RCE in Langflow versions <1.3.0
CVE-2025-3248CRITICALbajo ataqueransomware17 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
GitHub PoC
CVE-2024-28397 - Remote Code Execution From Vulnerable JS2PY
CVE-2024-28397MEDIUM17 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-22600MEDIUMbajo ataque17 sep 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RIESGO
abrir ↗
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve remote code execution.
CVE-2024-28397MEDIUM17 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque16 sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
CVE-2025-8311CRITICALwebappsmultiple16 sep 2025
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RIESGO
abrir ↗
Exploit-DB
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
CVE-2025-10046MEDIUMwebappsmultiple16 sep 2025
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1708HIGHbajo ataqueransomware16 sep 2025
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALbajo ataqueransomware16 sep 2025
Authentication bypass using an alternate path or channel
100RIESGO
abrir ↗
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
CVE-2021-43579—remotemultiple16 sep 2025
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RIESGO
abrir ↗
GitHub PoC
PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability
CVE-2025-20265CRITICAL16 sep 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware16 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗
Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
CVE-2025-47917HIGHlocalmultiple16 sep 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-24799HIGH16 sep 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir ↗
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 sep 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RIESGO
abrir ↗
Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
CVE-2025-8573LOWwebappsmultiple16 sep 2025
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RIESGO
abrir ↗
GitHub PoC★ 2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALbajo ataque16 sep 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir ↗
Exploit-DB
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
CVE-2025-55911MEDIUMremotemultiple16 sep 2025
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
33RIESGO
abrir ↗
GitHub PoC★ 2
Example PoC for CVE-2025-24813 (Tomcat RCE)
CVE-2025-24813CRITICALbajo ataque16 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927—webappsmultiple16 sep 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RIESGO
abrir ↗
GitHub PoC
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALbajo ataqueransomware16 sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗
Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
CVE-2025-24893CRITICALbajo ataquewebappsmultiple16 sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗
Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
CVE-2025-57642HIGHwebappsmultiple16 sep 2025
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RIESGO
abrir ↗
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALbajo ataque16 sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
← anteriorpágina 272 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.