Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
VulnCheck XDB
initial-access
CVE-2025-1562CRITICAL22 jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RIESGO
abrir ↗
GitHub PoC★ 1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHbajo ataque22 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-1562CRITICAL22 jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware22 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2023-33538HIGHbajo ataque22 jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware22 jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗
GitHub PoC★ 17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL22 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗
GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CVE-2018-9035—22 jun 2025
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2024-35250HIGHbajo ataque21 jun 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque21 jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
GitHub PoC
PoC environment and exploit for the Apache Tomcat on Windows Remote Code Execution Vulnerability
CVE-2017-12615HIGHbajo ataqueransomware21 jun 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-4123HIGH21 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir ↗
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL21 jun 2025
Xz: malicious code in distributed source
70RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2025-2539HIGH21 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RIESGO
abrir ↗
GitHub PoC
CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境
CVE-2021-44228CRITICALbajo ataqueransomware21 jun 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
GitHub PoC★ 4
mbanyamer/PX4-Military-UAV-Autopilot-1.12.3-Stack-Buffer-Overflow-Exploit-CVE-2025-5640-
CVE-2025-5640MEDIUM21 jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RIESGO
abrir ↗
GitHub PoC★ 2
punitdarji/Grafana-cve-2025-4123
CVE-2025-4123HIGH21 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir ↗
GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
CVE-2025-24813CRITICALbajo ataque21 jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗
Exploit-DB
FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
CVE-2024-50562MEDIUMremotemultiple20 jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RIESGO
abrir ↗
GitHub PoC
This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-1578—20 jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir ↗
GitHub PoC
Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell)
CVE-2014-6287CRITICALbajo ataque20 jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
GitHub PoC
Tiny File Manager <= 2.4.6 - Remote Code Execution (RCE)
CVE-2021-40964—20 jun 2025
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RIESGO
abrir ↗
GitHub PoC
CVE-2024-50562 is a session management vulnerability in Fortinet SSL-VPN portals
CVE-2024-50562MEDIUM20 jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RIESGO
abrir ↗
GitHub PoC
typicalsmc/CVE-2025-49132-PoC
CVE-2025-49132CRITICAL20 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗
Exploit-DB
Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
CVE-2025-47957HIGHlocalwindows20 jun 2025
Microsoft Word Remote Code Execution Vulnerability
41RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2025-6019HIGH20 jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
CVE-2025-1974CRITICALremotemultiple20 jun 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque20 jun 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque20 jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-41352CRITICALbajo ataqueransomware19 jun 2025
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir ↗
← anteriorpágina 325 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.