Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
71.957 exploits
GitHub PoC21
RSC Detect CVE 2025 55182
CVE-2025-55182CRITICALbajo ataqueransomware20 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can neutralize a critical Next.js/React Server Actions RCE (CVE-2025-55182 “React2Shell”), with side-by-side safe vs unsafe deployments and exploit logs
CVE-2025-55182CRITICALbajo ataqueransomware20 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
open-flaw/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478) Full Script
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
lamaper/CVE-2025-55182-Toolbox
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool performs passive detection, active fingerprinting, and RCE exploitation testing.
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit
CVE-2025-13486CRITICAL19 dic 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir
GitHub PoC6
PoC for CVE-2025-37164
CVE-2025-37164CRITICALbajo ataque19 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware19 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-37164CRITICALbajo ataque19 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALbajo ataqueransomware19 dic 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque19 dic 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34442MEDIUM19 dic 2025
AVideo < 20.1 System Path Disclosure via Public API
28RIESGO
abrir
GitHub PoC16
Detection for CVE-2025-68461
CVE-2025-68461HIGHbajo ataque19 dic 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34441MEDIUM19 dic 2025
AVideo < 20.1 User Information Disclosure via Public API
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-13486CRITICAL19 dic 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34433CRITICAL19 dic 2025
AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
63RIESGO
abrir
Metasploit300
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVE-2025-14847HIGHbajo ataque19 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain, featuring optional proxy support, automated session elevation, and dynamic command injection via the print scripting engine. Designed for security auditing and authorized penetration testing.
CVE-2023-27350CRITICALbajo ataqueransomware19 dic 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC4
This is a Proof-Of-Concept of CVE-2025-63353
CVE-2025-63353CRITICAL18 dic 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RIESGO
abrir
GitHub PoC1
CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000 series appliances.
CVE-2025-40602MEDIUMbajo ataque18 dic 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RIESGO
abrir
GitHub PoC3
Detection for CVE-2025-40602
CVE-2025-40602MEDIUMbajo ataque18 dic 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RIESGO
abrir
GitHub PoC
Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:
CVE-2025-67888HIGH18 dic 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware18 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
cyberok-org/CVE-2025-67887
CVE-2025-67887CRITICAL18 dic 2025
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RIESGO
abrir
GitHub PoC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security researchers and defenders understand the issue and validate fixes.
CVE-2025-33053HIGHbajo ataque18 dic 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
Detection for CVE-2025-37164
CVE-2025-37164CRITICALbajo ataque18 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
GitHub PoC
This repo describes about cve-2021-29447 and a small script for exploiting automatically
CVE-2021-29447HIGH18 dic 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
React2Shell Vulnerability Verification Script (React2Shell also known as CVE-2025-55182).
CVE-2025-55182CRITICALbajo ataqueransomware18 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 143 / 2399siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.