Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.407exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
GitHub PoC
shoucheng3/x-stream__xstream_CVE-2013-7285_1-4-6
CVE-2013-7285—19 ago 2025
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RIESGO
abrir ↗
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57788MEDIUM19 ago 2025
Unauthorized API Access Risk
28RIESGO
abrir ↗
GitHub PoC
www-spam/CVE-2024-53900
CVE-2024-53900CRITICAL19 ago 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
CVE-2023-49109CRITICAL19 ago 2025
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir ↗
GitHub PoC
R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
CVE-2025-29927CRITICAL19 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC★ 1
charanvoonna/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware19 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware19 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC★ 1
This is a rewritten exploit to work with php
CVE-2025-49113CRITICALbajo ataque19 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
GitHub PoC★ 8
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution
CVE-2025-8723CRITICAL19 ago 2025
Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
53RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque19 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2024-53900CRITICAL19 ago 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗
GitHub PoC
CVE-2025-8088
CVE-2025-8088HIGHbajo ataqueransomware19 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware19 ago 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57791MEDIUM19 ago 2025
Argument Injection Vulnerability in CommServe
33RIESGO
abrir ↗
GitHub PoC★ 3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 ago 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗
GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2013-3900MEDIUMbajo ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-8739—18 ago 2025
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗
GitHub PoC★ 1
harutomo-jp/CVE-2024-28397-RCE
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
CVE-2022-3782CRITICAL18 ago 2025
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RIESGO
abrir ↗
GitHub PoC★ 5
CVE PoC
CVE-2013-3900MEDIUMbajo ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗
Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass
CVE-2015-6830—remotephp18 ago 2025
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo
23RIESGO
abrir ↗
Exploit-DB
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
CVE-2025-7766HIGHwebappsmultiple18 ago 2025
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RIESGO
abrir ↗
GitHub PoC★ 2
Proof of concept for CVE-2020-36708
CVE-2020-36708CRITICAL18 ago 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir ↗
Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
CVE-2024-28623MEDIUMwebappsmultiple18 ago 2025
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RIESGO
abrir ↗
Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
CVE-2024-54761MEDIUMwebappsmultiple18 ago 2025
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir ↗
GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
CVE-2025-49113CRITICALbajo ataque18 ago 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗
GitHub PoC
chan-068/CVE-2024-0520_try
CVE-2024-0520CRITICAL18 ago 2025
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RIESGO
abrir ↗
GitHub PoC★ 3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
CVE-2025-49132CRITICAL18 ago 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗
← anteriorpágina 285 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.