Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.331exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Oracle E-Business Suite CVE-2025-61882 RCE
CVE-2025-61882CRITICALbajo ataqueransomware04 oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir
Metasploit600
Centreon authenticated command injection leading to RCE via broker engine "reload" parameter
CVE-2025-5946HIGH24 sep 2025
RCE via the poller reload feature available only to user with high privilege
41RIESGO
abrir
Metasploit600
Flowise JS Injection RCE
CVE-2025-59528CRITICAL13 sep 2025
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
CVE-2025-60787HIGH09 sep 2025
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir
Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
CVE-2025-57819CRITICALbajo ataque28 ago 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57788MEDIUM19 ago 2025
Unauthorized API Access Risk
28RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57790HIGH19 ago 2025
Path Traversal Vulnerability
41RIESGO
abrir
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57791MEDIUM19 ago 2025
Argument Injection Vulnerability in CommServe
33RIESGO
abrir
Metasploit600
Flowise Custom MCP Remote Code Execution
CVE-2025-8943CRITICAL14 ago 2025
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RIESGO
abrir
Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
CVE-2025-34152CRITICAL07 ago 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
CVE-2025-50286HIGH07 ago 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir
Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
CVE-2025-7441CRITICAL04 ago 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
CVE-2026-32985CRITICAL04 ago 2025
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RIESGO
abrir
Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
CVE-2025-34300CRITICAL16 jul 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir
Metasploit600
PivotX Remote Code Execution
CVE-2025-52367MEDIUM10 jul 2025
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53771MEDIUM08 jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
50RIESGO
abrir
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-49706MEDIUMbajo ataqueransomware08 jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53770CRITICALbajo ataqueransomware08 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-49704HIGHbajo ataqueransomware08 jul 2025
Microsoft SharePoint Remote Code Execution Vulnerability
88RIESGO
abrir
Metasploit600
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVE-2025-47812CRITICALbajo ataque30 jun 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Metasploit300
Sudo Chroot 1.9.17 Privilege Escalation
CVE-2025-32463CRITICALbajo ataque30 jun 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
Metasploit300
Marvell QConvergeConsole Path Traversal (CVE-2025-6793)
CVE-2025-6793CRITICAL27 jun 2025
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
48RIESGO
abrir
Metasploit600
PandoraFMS Netflow Authenticated Remote Code Execution
CVE-2025-5306HIGH27 jun 2025
Command Injection in Netflow path
48RIESGO
abrir
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51977MEDIUM25 jun 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51978CRITICAL25 jun 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir
Metasploit600
Pterodactyl Panel CVE-2025-49132 Remote Code Execution
CVE-2025-49132CRITICAL19 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
Metasploit600
Sitecore XP CVE-2025-34511 Post-Authentication File Upload
CVE-2025-34511HIGH17 jun 2025
Sitecore PowerShell Extension RCE via Unrestricted Upload
41RIESGO
abrir
Metasploit600
Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution
CVE-2025-34510HIGH17 jun 2025
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
41RIESGO
abrir
Metasploit300
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVE-2025-33053HIGHbajo ataque11 jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Pandora ITSM authenticated command injection leading to RCE via the backup function
CVE-2025-4653HIGH10 jun 2025
Remote Code Execution leads to Command Injection
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.