Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
n8n Workflow Expression Remote Code Execution
CVE-2025-68613CRITICALbajo ataque10 jun 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
Metasploit300
Listmonk Insecure Sprig Template Functions Environment Disclosure
CVE-2025-49136CRITICAL08 jun 2025
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
43RIESGO
abrir
Metasploit600
Skyvern SSTI Remote Code Execution
CVE-2025-49619HIGH07 jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RIESGO
abrir
Metasploit600
Roundcube Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALbajo ataque02 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
Metasploit300
Remote for Mac Unauthenticated RCE
CVE-2025-34089CRITICAL27 may 2025
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir
Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
CVE-2025-48828CRITICAL23 may 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir
Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
CVE-2025-48827CRITICAL23 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
Metasploit600
Invision Community 5.0.6 customCss RCE
CVE-2025-47916CRITICAL16 may 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir
Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
CVE-2025-4428HIGHbajo ataque13 may 2025
Remote Code Execution
100RIESGO
abrir
Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
CVE-2025-4427MEDIUMbajo ataque13 may 2025
Authentication Bypass
100RIESGO
abrir
Metasploit300
WordPress Depicter Plugin SQL Injection (CVE-2025-2011)
CVE-2025-2011HIGH08 may 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
Metasploit600
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
CVE-2024-7399HIGHbajo ataque30 abr 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RIESGO
abrir
Metasploit600
Erlang OTP Pre-Auth RCE Scanner and Exploit
CVE-2025-32433CRITICALbajo ataque16 abr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
Metasploit600
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
CVE-2025-32432CRITICALbajo ataque14 abr 2025
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
Metasploit600
Web-Check Screenshot API Command Injection RCE
CVE-2025-32778CRITICAL12 abr 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir
Metasploit600
BentoML's runner server RCE
CVE-2025-32375CRITICAL09 abr 2025
Insecure Deserialization leads to RCE in BentoML's runner server
75RIESGO
abrir
Metasploit600
Langflow AI RCE
CVE-2025-3248CRITICALbajo ataqueransomware09 abr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
Metasploit600
BentoML RCE
CVE-2025-27520CRITICAL04 abr 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RIESGO
abrir
Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
CVE-2025-30406CRITICALbajo ataque03 abr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir
Metasploit300
Gladinet CentreStack/Triofox Path Traversal
CVE-2025-11371HIGHbajo ataque03 abr 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir
Metasploit500
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
CVE-2025-22457CRITICALbajo ataqueransomware03 abr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL03 abr 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir
Metasploit600
Appsmith RCE
CVE-2024-55964CRITICAL25 mar 2025
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea
43RIESGO
abrir
Metasploit600
WP User Registration and Membership Unauthenticated Privilege Escalation (CVE-2025-2563)
CVE-2025-2563HIGH24 mar 2025
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RIESGO
abrir
Metasploit300
Next.js Middleware Authorization Bypass Scanner
CVE-2025-29927CRITICAL21 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
Metasploit600
ICTBroadcast Unauthenticated Remote Code Execution
CVE-2025-2611CRITICAL19 mar 2025
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RIESGO
abrir
Metasploit600
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
CVE-2024-12971HIGH17 mar 2025
QuickShell Authenticated Command Injection
48RIESGO
abrir
Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
CVE-2025-3102HIGH13 mar 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir
Metasploit300
Sante PACS Server Path Traversal (CVE-2025-2264)
CVE-2025-2264HIGH13 mar 2025
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RIESGO
abrir
Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
CVE-2025-27007CRITICAL13 mar 2025
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.