Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
75.902 exploits
Exploit-DB
OpenPanel 0.3.4 - OS Command Injection
CVE-2024-53584CRITICALwebappsmultiple14 abr 2025
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware14 abr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
jakehomb/cve-2023-42793
CVE-2023-42793CRITICALbajo ataqueransomware14 abr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 abr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-44228CRITICALbajo ataqueransomware14 abr 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
pulentoski/Explotacion-CVE-2023-32315-Openfire
CVE-2023-32315HIGHbajo ataque14 abr 2025
Openfire administration console authentication bypass
100RIESGO
abrir
Exploit-DB
GestioIP 3.5.7 - Remote Command Execution (RCE)
CVE-2024-48760CRITICALremotemultiple14 abr 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RIESGO
abrir
GitHub PoC
AsierEgana/cve-2021-4034
CVE-2021-4034HIGHbajo ataque14 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-41773HIGHbajo ataqueransomware14 abr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
PoC for CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware14 abr 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
Metasploit600
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
CVE-2025-32432CRITICALbajo ataque14 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC12
Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass
CVE-2025-29927CRITICAL14 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
OpenPanel 0.3.4 - Directory Traversal
CVE-2024-53537CRITICALwebappsmultiple14 abr 2025
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RIESGO
abrir
Exploit-DB
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
CVE-2024-53582HIGHwebappsmultiple14 abr 2025
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RIESGO
abrir
Exploit-DB
SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
CVE-2024-47605MEDIUMwebappsmultiple14 abr 2025
Cross-site Scripting via insert media remote file oembed in silverstripe-asset-admin
33RIESGO
abrir
GitHub PoC
CVE-2024-4367
CVE-2024-4367MEDIUM14 abr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
Exploit-DB
GestioIP 3.5.7 - Cross-Site Request Forgery (CSRF)
CVE-2024-50858HIGHremotemultiple14 abr 2025
Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio
41RIESGO
abrir
Exploit-DB
GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
CVE-2024-50859MEDIUMremotemultiple14 abr 2025
The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma
33RIESGO
abrir
Exploit-DB
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
CVE-2024-50861MEDIUMremotemultiple14 abr 2025
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod
33RIESGO
abrir
Exploit-DB
Pimcore 11.4.2 - Stored cross site scripting
CVE-2024-11954MEDIUMwebappsmultiple14 abr 2025
Pimcore Search Document cross site scripting
33RIESGO
abrir
Exploit-DB
Pimcore customer-data-framework 4.2.0 - SQL injection
CVE-2024-11956MEDIUMwebappsmultiple14 abr 2025
Pimcore customer-data-framework list sql injection
33RIESGO
abrir
GitHub PoC
The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.
CVE-2018-1676313 abr 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
spyata123/CVE-2023-3128
CVE-2023-3128CRITICAL13 abr 2025
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
48RIESGO
abrir
GitHub PoC
ikerSandoval003/CVE-2021-4034
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Exploit de la vulneravilidad CVE-2021-4034
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
nagorealbisu/CVE-2021-4034
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL13 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque13 abr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
anteriorpágina 275 / 2531siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.