Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927—webappsmultiple16 sep 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RIESGO
abrir ↗
GitHub PoC★ 2
Example PoC for CVE-2025-24813 (Tomcat RCE)
CVE-2025-24813CRITICALbajo ataque16 sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC
Authentication bypass vulnerability in versions of the CrushFTP server.
CVE-2025-31161CRITICALbajo ataqueransomware15 sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir ↗
GitHub PoC
tranphuc2005/CVE-2017-9822
CVE-2017-9822HIGHbajo ataqueransomware15 sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir ↗
GitHub PoC★ 3
Langflow Remote Code Execution
CVE-2025-3248CRITICALbajo ataqueransomware15 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
GitHub PoC
0xDTC/js2py-Sandbox-Escape-CVE-2024-28397-RCE
CVE-2024-28397MEDIUM15 sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware15 sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque15 sep 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-12611—15 sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir ↗
GitHub PoC
tcetin704/CVE-2017-12611
CVE-2017-12611—15 sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2017-9822HIGHbajo ataqueransomware15 sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware14 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-48543HIGHbajo ataque14 sep 2025
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft
71RIESGO
abrir ↗
GitHub PoC
Shubhankargupta691/CVE-2024-42009
CVE-2024-42009CRITICALbajo ataque14 sep 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3_2_1_fixed
CVE-2023-49109CRITICAL14 sep 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALbajo ataque14 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC
A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution.
CVE-2025-8088HIGHbajo ataqueransomware14 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264HIGH14 sep 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RIESGO
abrir ↗
GitHub PoC★ 1
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
CVE-2025-57819CRITICALbajo ataque14 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
GitHub PoC
Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to 2.4.51+, CGI disable, firewall) and published the analysis on GitHub.
CVE-2021-41773HIGHbajo ataqueransomware14 sep 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque13 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
Metasploit600
Flowise JS Injection RCE
CVE-2025-59528CRITICAL13 sep 2025
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir ↗
GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
CVE-2024-9264CRITICAL13 sep 2025
Grafana SQL Expressions allow for remote code execution
85RIESGO
abrir ↗
GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CVE-2025-54309CRITICALbajo ataque13 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
GitHub PoC★ 1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
CVE-2007-2447—13 sep 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗
GitHub PoC
CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque13 sep 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware13 sep 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque13 sep 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗
GitHub PoC★ 7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL13 sep 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque13 sep 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗
← anteriorpágina 273 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.