Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
GLPI Inventory Plugin Unauthenticated Blind Boolean SQLi
CVE-2025-24799HIGH12 mar 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
Metasploit600
Tomcat Partial PUT Java Deserialization
CVE-2025-24813CRITICALbajo ataque10 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Metasploit300
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
CVE-2025-30005HIGH02 mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
36RIESGO
abrir
Metasploit300
Xorcom CompletePBX Authenticated File Disclosure via Backup Download
CVE-2025-2292MEDIUM02 mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
28RIESGO
abrir
Metasploit600
Xorcom CompletePBX Authenticated Command Injection via Task Scheduler
CVE-2025-30004HIGH02 mar 2025
Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
36RIESGO
abrir
Metasploit600
Remote Code Execution Vulnerability in XWiki Platform (CVE-2025-24893)
CVE-2025-24893CRITICALbajo ataque20 feb 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Metasploit600
SPIP Saisies Plugin Unauthenticated RCE
CVE-2025-71243CRITICAL19 feb 2025
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RIESGO
abrir
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-24865CRITICAL13 feb 2025
mySCADA myPRO Manager Missing Authentication for Critical Function
43RIESGO
abrir
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-22896CRITICAL13 feb 2025
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RIESGO
abrir
Metasploit300
Audiobookshelf Unauthenticated API Authentication Bypass Scanner
CVE-2025-25205HIGH12 feb 2025
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
36RIESGO
abrir
Metasploit600
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
CVE-2025-24016CRITICALbajo ataque10 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
Metasploit600
InvokeAI RCE
CVE-2024-12029CRITICAL07 feb 2025
Remote Code Execution via Model Deserialization in invoke-ai/invokeai
63RIESGO
abrir
Metasploit600
D-Tale RCE
CVE-2024-3408CRITICAL05 feb 2025
Authentication Bypass and RCE in man-group/dtale
85RIESGO
abrir
Metasploit600
D-Tale RCE
CVE-2025-065505 feb 2025
15RIESGO
abrir
Metasploit600
Unauthenticated RCE in NetAlertX
CVE-2024-46506CRITICAL30 ene 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RIESGO
abrir
Metasploit300
NetAlertX File Read Vulnerability
CVE-2024-48766HIGH30 ene 2025
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RIESGO
abrir
Metasploit600
Cacti Graph Template authenticated RCE versions prior to 1.2.29
CVE-2025-24367HIGH27 ene 2025
Cacti allows Arbitrary File Creation leading to RCE
48RIESGO
abrir
Metasploit600
GestioIP 3.5.7 Remote Command Execution
CVE-2024-48760CRITICAL14 ene 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RIESGO
abrir
Metasploit300
Car Rental System 1.0 File Upload RCE (Authenticated)
CVE-2024-57487MEDIUM13 ene 2025
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a
28RIESGO
abrir
Metasploit300
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
CVE-2024-57727CRITICALbajo ataqueransomware12 ene 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RIESGO
abrir
Metasploit600
Remote Code Execution Vulnerability in Vvveb
CVE-2025-8518MEDIUM10 ene 2025
givanz Vvveb Code Editor code.php save code injection
28RIESGO
abrir
Metasploit600
Sitecore CVE-2025-27218 BinaryFormatter Deserialization Exploit
CVE-2025-27218MEDIUM06 ene 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RIESGO
abrir
Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
CVE-2025-3096CRITICAL04 ene 2025
Clinics Patient Management System SQL Injection
43RIESGO
abrir
Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
CVE-2022-2297MEDIUM04 ene 2025
SourceCodester Clinics Patient Management System unrestricted upload
28RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48455LOW27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48456HIGH27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
41RIESGO
abrir
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48457HIGH27 dic 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
36RIESGO
abrir
Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVE-2024-56145CRITICALbajo ataque19 dic 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
Metasploit600
Windows Cloud File Mini Filer Driver Heap Overflow
CVE-2024-30085HIGH19 dic 2024
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALbajo ataque16 dic 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.