Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
72.018 exploits
GitHub PoC7
For CVE-2025-55182 and CVE-2025-66478 Security Response
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
React/Next.js React4Shell RCE CVE-2025-55182 checker
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
RCE Auto exploit for CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2451
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC117
Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
sudo-Yangziran/CVE-2025-55182POC
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC58
Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware.
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
A Comprehensive CVE-2025-55182 Detection and Security Assessment Tool
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
dissy123/cve-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC60
Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
a realistic POC demonstrating the missing `hasOwnProperty` check in react-server-dom-webpack@19.0.0
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC22
a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test and understand the vulnerability.
CVE-2025-55182CRITICALbajo ataqueransomware04 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC12
Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) “Flight” protocol.
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC113
A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-2646903 dic 2025
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
60RIESGO
abrir
GitHub PoC
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC4
santihabib/CVE-2025-55182-analysis
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
CVE-2017-647803 dic 2025
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RIESGO
abrir
GitHub PoC798
CVE-2025-55182 POC
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC14
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
CVE-2018-25080LOW03 dic 2025
MobileDetect Example session_example.php initLayoutType cross site scripting
28RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque03 dic 2025
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
CVE-2017-1573403 dic 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
CVE-2017-1573503 dic 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALbajo ataqueransomware03 dic 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
Exploit-DB
openSIS Community Edition 8.0 - SQL Injection
CVE-2021-4061703 dic 2025
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
23RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
CVE-2020-20969HIGH03 dic 2025
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RIESGO
abrir
Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
CVE-2017-1580803 dic 2025
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RIESGO
abrir
Exploit-DB
RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)
CVE-2020-1571803 dic 2025
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php sc
38RIESGO
abrir
anteriorpágina 167 / 2401siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.