Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.407exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.608VulnCheck XDB 9133Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.192 exploits
GitHub PoC
shoucheng3/x-stream__xstream_CVE-2013-7285_1-4-6
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Unauthorized API Access Risk
28RIESGO
abrir ↗GitHub PoC
www-spam/CVE-2024-53900
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
Remote Code Execution in Apache Dolphinscheduler
48RIESGO
abrir ↗GitHub PoC
R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC★ 1
charanvoonna/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
This is a rewritten exploit to work with php
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗GitHub PoC★ 8
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution
Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
53RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗VulnCheck XDB
infoleak
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Argument Injection Vulnerability in CommServe
33RIESGO
abrir ↗GitHub PoC★ 3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RIESGO
abrir ↗GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗GitHub PoC★ 1
harutomo-jp/CVE-2024-28397-RCE
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RIESGO
abrir ↗Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo
23RIESGO
abrir ↗Exploit-DB
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RIESGO
abrir ↗GitHub PoC★ 2
Proof of concept for CVE-2020-36708
Epsilon Framework Themes (Various Versions) - Function Injection
75RIESGO
abrir ↗Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RIESGO
abrir ↗Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RIESGO
abrir ↗GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗GitHub PoC
chan-068/CVE-2024-0520_try
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RIESGO
abrir ↗GitHub PoC★ 3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.