Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.329exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Control Web Panel /admin/index.php Unauthenticated RCE
CVE-2025-67888HIGH16 dic 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RIESGO
abrir
Metasploit600
HPE OneView unauthenticated RCE
CVE-2025-37164CRITICALbajo ataque16 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
Metasploit600
FreeBSD rtsold/rtsol DNSSL Command Injection
CVE-2025-14558HIGH16 dic 2025
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-61675HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RIESGO
abrir
Metasploit300
Gladinet CentreStack/Triofox Access Ticket Forge
CVE-2025-14611HIGHbajo ataque10 dic 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-6647803 dic 2025
15RIESGO
abrir
Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
CVE-2025-13486CRITICAL02 dic 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RIESGO
abrir
Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
CVE-2025-12548CRITICAL01 dic 2025
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66301HIGH01 dic 2025
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66294HIGH01 dic 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RIESGO
abrir
Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
CVE-2025-58360HIGHbajo ataque25 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-9316MEDIUM17 nov 2025
N-central unauthenticated sessionID generation
60RIESGO
abrir
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-11700HIGH17 nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RIESGO
abrir
Metasploit300
Fortinet FortiWeb create new local admin
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-58034MEDIUMbajo ataque14 nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-64446CRITICALbajo ataque14 nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
Metasploit600
FreePBX filestore authenticated command injection
CVE-2025-64328HIGHbajo ataque08 nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RIESGO
abrir
Metasploit600
Monsta FTP downloadFile Remote Code Execution
CVE-2025-34299CRITICAL07 nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVE-2025-11749CRITICAL04 nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RIESGO
abrir
Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
CVE-2025-8489CRITICAL30 oct 2025
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RIESGO
abrir
Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
CVE-2025-62368CRITICAL28 oct 2025
Taiga Authenticated Remote Code Execution
43RIESGO
abrir
Metasploit600
Magento SessionReaper
CVE-2025-54236CRITICALbajo ataque22 oct 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir
Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
CVE-2025-59287CRITICALbajo ataque14 oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
CVE-2025-52691CRITICALbajo ataqueransomware09 oct 2025
Upload Arbitrary Files
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.