Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
GitHub PoC★ 8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
CVE-2025-9074CRITICAL03 sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-6019HIGH03 sep 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALbajo ataque03 sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir ↗
GitHub PoC★ 1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CVE-2024-51568CRITICAL02 sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir ↗
GitHub PoC★ 1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
CVE-2025-23266CRITICAL02 sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir ↗
GitHub PoC★ 2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL02 sep 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir ↗
GitHub PoC★ 1
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
CVE-2024-47875CRITICAL02 sep 2025
DOMPurify nesting-based mXSS
48RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-51568CRITICAL02 sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RIESGO
abrir ↗
GitHub PoC
Python3 port of the original Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
CVE-2019-10945—02 sep 2025
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir ↗
GitHub PoC★ 1
Version detection PowerShell
CVE-2025-7775CRITICALbajo ataque02 sep 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir ↗
GitHub PoC★ 1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
CVE-2025-34300CRITICAL01 sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque01 sep 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir ↗
GitHub PoC★ 7
FreePBX SQL Injection Exploit
CVE-2025-57819CRITICALbajo ataque01 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALbajo ataque01 sep 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir ↗
GitHub PoC★ 1
a proof of concept of CVE-2024-53677
CVE-2024-53677CRITICAL01 sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL01 sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-34300CRITICAL01 sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2018-19207—01 sep 2025
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALbajo ataqueransomware01 sep 2025
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3515HIGH01 sep 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware01 sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir ↗
GitHub PoC★ 1
HTML cache poisoning through unsafe reflections
CVE-2025-53693CRITICAL01 sep 2025
HTML Cache Poisoning through Unsafe Reflections
53RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALbajo ataque01 sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware31 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
GitHub PoC★ 1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RIESGO
abrir ↗
GitHub PoC★ 2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALbajo ataque31 ago 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque31 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
GitHub PoC★ 18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 ago 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-48307CRITICAL31 ago 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RIESGO
abrir ↗
← anteriorpágina 278 / 2703siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.