Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.331exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.484VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Oracle E-Business Suite CVE-2025-61882 RCE
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir ↗Metasploit600
Centreon authenticated command injection leading to RCE via broker engine "reload" parameter
RCE via the poller reload feature available only to user with high privilege
41RIESGO
abrir ↗Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir ↗Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Unauthorized API Access Risk
28RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Path Traversal Vulnerability
41RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Argument Injection Vulnerability in CommServe
33RIESGO
abrir ↗Metasploit600
Flowise Custom MCP Remote Code Execution
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RIESGO
abrir ↗Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir ↗Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir ↗Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RIESGO
abrir ↗Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir ↗Metasploit600
PivotX Remote Code Execution
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
50RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
100RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Remote Code Execution Vulnerability
88RIESGO
abrir ↗Metasploit600
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗Metasploit300
Sudo Chroot 1.9.17 Privilege Escalation
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Metasploit300
Marvell QConvergeConsole Path Traversal (CVE-2025-6793)
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
48RIESGO
abrir ↗Metasploit600
PandoraFMS Netflow Authenticated Remote Code Execution
Command Injection in Netflow path
48RIESGO
abrir ↗Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir ↗Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗Metasploit600
Pterodactyl Panel CVE-2025-49132 Remote Code Execution
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir ↗Metasploit600
Sitecore XP CVE-2025-34511 Post-Authentication File Upload
Sitecore PowerShell Extension RCE via Unrestricted Upload
41RIESGO
abrir ↗Metasploit600
Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
41RIESGO
abrir ↗Metasploit300
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
Pandora ITSM authenticated command injection leading to RCE via the backup function
Remote Code Execution leads to Command Injection
36RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.