Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL03 abr 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
Metasploit300
Gladinet CentreStack/Triofox Path Traversal
CVE-2025-11371HIGHbajo ataque03 abr 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir
GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
CVE-2024-53900CRITICAL03 abr 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir
Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
CVE-2025-30406CRITICALbajo ataque03 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
CVE-2025-29927CRITICAL03 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
CVE-2024-4007HIGHwebappsphp03 abr 2025
Hard coded default credential contained in install package
41RIESGO
abrir
Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
CVE-2024-44762MEDIUMwebappsperl03 abr 2025
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RIESGO
abrir
GitHub PoC
Next.js and the corrupt middleware...TRY TO HACK IT..!
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
CVE-2025-29927CRITICAL02 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
CVE-2022-22536CRITICALbajo ataqueremotemultiple02 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
GitHub PoC2
Detection of malicious VHD files for CVE-2025-24985
CVE-2025-24985HIGHbajo ataque02 abr 2025
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
71RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-44026CRITICALbajo ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
CVE-2025-2005CRITICAL02 abr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM02 abr 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
Exploit-DB
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
CVE-2024-42831MEDIUMwebappsphp02 abr 2025
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394202 abr 2025
Remote Code Execution in Apache Unomi
50RIESGO
abrir
GitHub PoC
corsisechero/CVE-2019-9193byVulHub
CVE-2019-919302 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC
0xshaheen/CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
mass scan for CVE-2025-30208
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
Exploit-DB
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
CVE-2024-6298CRITICALwebappsmultiple02 abr 2025
remote code execution
53RIESGO
abrir
GitHub PoC
A demo exploit for CVE-2021-44026, a SQL injection in Roundcube
CVE-2021-44026CRITICALbajo ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
CVE-2025-2594HIGH02 abr 2025
User Registration & Membership < 4.1.3 - Authentication Bypass
41RIESGO
abrir
Exploit-DB
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
CVE-2024-6209CRITICALwebappsphp02 abr 2025
unauthorized file access
53RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919302 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALbajo ataque01 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL01 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALbajo ataqueransomware01 abr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
GitHub PoC
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
CVE-2023-29357CRITICALbajo ataqueransomware01 abr 2025
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
anteriorpágina 284 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.