Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RIESGO
abrir ↗GitHub PoC
CVE-2025-53833
LaRecipe is vulnerable to Server-Side Template Injection attacks
63RIESGO
abrir ↗Exploit-DB
MikroTik RouterOS 7.19.1 - Reflected XSS
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
33RIESGO
abrir ↗GitHub PoC
rpc.py 0.6.0 - Remote Code Execution (RCE)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RIESGO
abrir ↗Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RIESGO
abrir ↗GitHub PoC
malaya-m/cve-2013-3900-remediation-report
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir ↗Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
Detection for CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗GitHub PoC
nguyentranbaotran/cve-2025-48384-poc
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir ↗GitHub PoC
Floodnut/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Exploit-DB
TOTOLINK N300RB 8.54 - Command Execution
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti
41RIESGO
abrir ↗GitHub PoC★ 5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗VulnCheck XDB
client-side
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC
Kalidas-7/CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
WP Publications <= 1.2 - Admin+ Stored XSS
33RIESGO
abrir ↗VulnCheck XDB
infoleak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗GitHub PoC★ 2
joelczk/CVE-2025-52688
Command Injection Vulnerability in the OmniAccess Stellar Web Management Interface
53RIESGO
abrir ↗Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
Windows Graphics Component Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Exploit-DB
NodeJS 24.x - Path Traversal
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RIESGO
abrir ↗Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗GitHub PoC★ 1
krypton-0x00/CVE-2025-32463-Chwoot-POC
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Exploit-DB
PivotX 3.0.0 RC3 - Remote Code Execution (RCE)
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir ↗GitHub PoC
ECHO6789/CVE-2025-48384-submodule
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No login required. Fully automated.
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.