Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
GitHub PoC
rashedhasan090/cve-2025-55182-mitigator
CVE-2025-55182CRITICALbajo ataqueransomware18 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware17 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC6
Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of cryptographic signatures (CWE‑347) in the handling of SAML responses for the FortiCloud SSO login feature.
CVE-2025-59718CRITICALbajo ataque17 dic 2025
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque17 dic 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1
CVE-2025-14700CRITICAL17 dic 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RIESGO
abrir
GitHub PoC
Improved poc of CVE-2017-0785 on DS-MDP002
CVE-2017-078517 dic 2025
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALbajo ataqueransomware17 dic 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC
React2shell vulnerable lab (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware17 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198
CVE-2024-27198CRITICALbajo ataqueransomware17 dic 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC2
Proof-of-concept research tool for CVE-2025-55182, a critical unauthenticated RCE in Next.js App Router caused by server-side object injection in React Server Components and Server Actions, including UTF-16LE WAF evasion techniques.
CVE-2025-55182CRITICALbajo ataqueransomware17 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Metasploit600
ChurchCRM Unauthenticated RCE via Setup Page
CVE-2025-62521CRITICAL17 dic 2025
ChurchCRM has unauthenticated RCE in its Install Wizard
43RIESGO
abrir
Metasploit300
ChurchCRM Database Restore RCE 6.2.0
CVE-2025-68109CRITICAL17 dic 2025
ChurchCRM vulnerable to RCE with database restore functionality
43RIESGO
abrir
GitHub PoC1
React2Shell
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2022-0492
CVE-2022-0492HIGHbajo ataque16 dic 2025
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
Metasploit600
FreeBSD rtsold/rtsol DNSSL Command Injection
CVE-2025-14558HIGH16 dic 2025
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
GitHub PoC1
This repository documents three security vulnerabilities discovered in FreePBX (CVE-2025-66039, CVE-2025-61678, CVE-2025-61675), including analysis, impact, and proof-of-concept details for security research and awareness purposes.
CVE-2025-66039CRITICAL16 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit600
Control Web Panel /admin/index.php Unauthenticated RCE
CVE-2025-67888HIGH16 dic 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RIESGO
abrir
Metasploit600
HPE OneView unauthenticated RCE
CVE-2025-37164CRITICALbajo ataque16 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
Exploit-DB
Summar Employee Portal 3.98.0 - Authenticated SQL Injection
CVE-2025-40677HIGHwebappsmultiple16 dic 2025
SQL injection vulnerability in Summar Software´s Portal del Empleado
41RIESGO
abrir
GitHub PoC
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability."
CVE-2017-0144HIGHbajo ataqueransomware16 dic 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC1
This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive information like NTLM Exposure.
CVE-2025-24071MEDIUM16 dic 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
d0cnull/nextjs-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Quyida to‘liq LAB rejasi: demo-vulnerable app → Python PoC → Metasploit exploit skeleton
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Exploit-DB
esm-dev 136 - Path Traversal
CVE-2025-59342MEDIUMwebappsmultiple16 dic 2025
esm.sh writes arbitrary files via path traversal in `X-Zone-Id` header
48RIESGO
abrir
GitHub PoC
CVE-1999-0678- /doc directory browsable
CVE-1999-067816 dic 2025
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
S-Mughal/NextJS-app-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware16 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 224 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.