Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.409exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
GitHub PoC★ 1
harutomo-jp/CVE-2024-28397-RCE
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
CVE-2024-28397MEDIUM18 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
CVE-2024-28623MEDIUMwebappsmultiple18 ago 2025
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RIESGO
abrir ↗
GitHub PoC
CVE-2015-6967 PoC Exploit
CVE-2015-6967—18 ago 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2013-3900MEDIUMbajo ataque18 ago 2025
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗
GitHub PoC★ 1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 ago 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RIESGO
abrir ↗
GitHub PoC★ 3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir ↗
GitHub PoC
Demo of CVE-2025-29927 for secure programming class
CVE-2025-29927CRITICAL17 ago 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗
GitHub PoC★ 2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
CVE-2025-8088HIGHbajo ataqueransomware17 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALbajo ataque17 ago 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-32778CRITICAL17 ago 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir ↗
GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
CVE-2015-10141CRITICAL17 ago 2025
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RIESGO
abrir ↗
GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
CVE-2019-12185—17 ago 2025
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RIESGO
abrir ↗
GitHub PoC★ 21
Detection for CVE-2025-8875 & CVE-2025-8876
CVE-2025-8875CRITICALbajo ataque17 ago 2025
Insecure Deserialization Vulnerability
78RIESGO
abrir ↗
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
CVE-2020-5410HIGHbajo ataque17 ago 2025
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir ↗
GitHub PoC★ 5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
CVE-2024-28397MEDIUM17 ago 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir ↗
GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CVE-2011-2732—17 ago 2025
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque16 ago 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
CVE-2023-37582CRITICAL16 ago 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RIESGO
abrir ↗
GitHub PoC★ 1
Ash1996x/CVE-2025-50154-Aggressor-Script
CVE-2025-50154MEDIUM16 ago 2025
Microsoft Windows File Explorer Spoofing Vulnerability
45RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
CVE-2011-4367—16 ago 2025
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RIESGO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
CVE-2018-7422—16 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2018-7422—16 ago 2025
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir ↗
GitHub PoC
Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version 1.890 (CVE-2019-15107), ultimately gaining full control over the target system.
CVE-2019-15107CRITICALbajo ataqueransomware16 ago 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware16 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
CVE-2023-37908CRITICAL16 ago 2025
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RIESGO
abrir ↗
GitHub PoC
shoucheng3/apache__shiro_CVE-2023-34478_1-11-0
CVE-2023-34478CRITICAL16 ago 2025
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
48RIESGO
abrir ↗
GitHub PoC★ 5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
CVE-2025-6934CRITICAL16 ago 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir ↗
GitHub PoC★ 36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
CVE-2025-8088HIGHbajo ataqueransomware16 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-8088HIGHbajo ataqueransomware15 ago 2025
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗
← anteriorpágina 286 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.