Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
n8n Workflow Expression Remote Code Execution
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir ↗Metasploit300
Listmonk Insecure Sprig Template Functions Environment Disclosure
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
43RIESGO
abrir ↗Metasploit600
Skyvern SSTI Remote Code Execution
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RIESGO
abrir ↗Metasploit600
Roundcube Post-Auth RCE via PHP Object Deserialization
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir ↗Metasploit300
Remote for Mac Unauthenticated RCE
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir ↗Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir ↗Metasploit600
vBulletin replaceAdTemplate Remote Code Execution
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir ↗Metasploit600
Invision Community 5.0.6 customCss RCE
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RIESGO
abrir ↗Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
Remote Code Execution
100RIESGO
abrir ↗Metasploit600
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
Authentication Bypass
100RIESGO
abrir ↗Metasploit300
WordPress Depicter Plugin SQL Injection (CVE-2025-2011)
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir ↗Metasploit600
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RIESGO
abrir ↗Metasploit600
Erlang OTP Pre-Auth RCE Scanner and Exploit
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗Metasploit600
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
Craft CMS Allows Remote Code Execution
100RIESGO
abrir ↗Metasploit600
Web-Check Screenshot API Command Injection RCE
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RIESGO
abrir ↗Metasploit600
BentoML's runner server RCE
Insecure Deserialization leads to RCE in BentoML's runner server
75RIESGO
abrir ↗Metasploit600
Langflow AI RCE
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗Metasploit600
BentoML RCE
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RIESGO
abrir ↗Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RIESGO
abrir ↗Metasploit300
Gladinet CentreStack/Triofox Path Traversal
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RIESGO
abrir ↗Metasploit500
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RIESGO
abrir ↗Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RIESGO
abrir ↗Metasploit600
Appsmith RCE
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea
43RIESGO
abrir ↗Metasploit600
WP User Registration and Membership Unauthenticated Privilege Escalation (CVE-2025-2563)
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RIESGO
abrir ↗Metasploit300
Next.js Middleware Authorization Bypass Scanner
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗Metasploit600
ICTBroadcast Unauthenticated Remote Code Execution
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RIESGO
abrir ↗Metasploit600
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
QuickShell Authenticated Command Injection
48RIESGO
abrir ↗Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir ↗Metasploit300
Sante PACS Server Path Traversal (CVE-2025-2264)
Santesoft Sante PACS Server Path Traversal Information Disclosure
48RIESGO
abrir ↗Metasploit600
WordPress SureTriggers (aka OttoKit) Combined Auth Bypass (CVE-2025-3102, CVE-2025-27007)
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.