Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
76.008 exploits
Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗Metasploit300
Gladinet CentreStack/Triofox Path Traversal
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir ↗GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
Hard coded default credential contained in install package
41RIESGO
abrir ↗Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RIESGO
abrir ↗GitHub PoC
Next.js and the corrupt middleware...TRY TO HACK IT..!
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir ↗GitHub PoC★ 2
Detection of malicious VHD files for CVE-2025-24985
Windows Fast FAT File System Driver Remote Code Execution Vulnerability
71RIESGO
abrir ↗VulnCheck XDB
client-side
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir ↗GitHub PoC★ 9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir ↗VulnCheck XDB
initial-access
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir ↗Exploit-DB
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex
33RIESGO
abrir ↗GitHub PoC
corsisechero/CVE-2019-9193byVulHub
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir ↗GitHub PoC★ 1
mass scan for CVE-2025-30208
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir ↗Exploit-DB
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
remote code execution
53RIESGO
abrir ↗GitHub PoC
A demo exploit for CVE-2021-44026, a SQL injection in Roundcube
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir ↗GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
User Registration & Membership < 4.1.3 - Authentication Bypass
41RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir ↗VulnCheck XDB
infoleak
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir ↗VulnCheck XDB
infoleak
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir ↗GitHub PoC
DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.