Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALbajo ataqueransomware29 dic 2025
Upload Arbitrary Files
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque29 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
amirali-ramezani/react2shell-CVE-2025-55182-
CVE-2025-55182CRITICALbajo ataqueransomware29 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque29 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC1
aexdyhaxor/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque29 dic 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-14611HIGHbajo ataque29 dic 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RIESGO
abrir
GitHub PoC
bodoinon/CVE-2024-10924
CVE-2024-10924CRITICAL28 dic 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC3
Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader
CVE-2025-14847HIGHbajo ataque28 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-10924CRITICAL28 dic 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
GitHub PoC
n8n CVE-2025-68613
CVE-2025-68613CRITICALbajo ataque28 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
CVE-2024-3094CRITICAL28 dic 2025
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2025-20393
CVE-2025-20393CRITICALbajo ataque28 dic 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RIESGO
abrir
GitHub PoC
The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation.
CVE-2025-14847HIGHbajo ataque28 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque28 dic 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC2
Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.
CVE-2025-24893CRITICALbajo ataque28 dic 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALbajo ataque28 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque28 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-536027 dic 2025
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque27 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware27 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
webmin/usermin 2.100
CVE-2024-44762MEDIUM27 dic 2025
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware27 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-46506CRITICAL27 dic 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque27 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque27 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque27 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque27 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
KingHacker353/R2C-CVE-2025-55182-66478
CVE-2025-55182CRITICALbajo ataqueransomware27 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719
CVE-2025-59718CRITICALbajo ataque27 dic 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RIESGO
abrir
GitHub PoC3
A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only
CVE-2025-68664CRITICAL27 dic 2025
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
60RIESGO
abrir
anteriorpágina 215 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.