Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
GLPI Inventory Plugin Unauthenticated Blind Boolean SQLi
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir ↗Metasploit600
Tomcat Partial PUT Java Deserialization
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗Metasploit300
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
36RIESGO
abrir ↗Metasploit300
Xorcom CompletePBX Authenticated File Disclosure via Backup Download
Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
28RIESGO
abrir ↗Metasploit600
Xorcom CompletePBX Authenticated Command Injection via Task Scheduler
Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
36RIESGO
abrir ↗Metasploit600
Remote Code Execution Vulnerability in XWiki Platform (CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗Metasploit600
SPIP Saisies Plugin Unauthenticated RCE
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RIESGO
abrir ↗Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
mySCADA myPRO Manager Missing Authentication for Critical Function
43RIESGO
abrir ↗Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RIESGO
abrir ↗Metasploit300
Audiobookshelf Unauthenticated API Authentication Bypass Scanner
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
36RIESGO
abrir ↗Metasploit600
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
Remote code execution in Wazuh server
100RIESGO
abrir ↗Metasploit600
InvokeAI RCE
Remote Code Execution via Model Deserialization in invoke-ai/invokeai
63RIESGO
abrir ↗Metasploit600
Unauthenticated RCE in NetAlertX
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RIESGO
abrir ↗Metasploit300
NetAlertX File Read Vulnerability
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RIESGO
abrir ↗Metasploit600
Cacti Graph Template authenticated RCE versions prior to 1.2.29
Cacti allows Arbitrary File Creation leading to RCE
48RIESGO
abrir ↗Metasploit600
GestioIP 3.5.7 Remote Command Execution
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RIESGO
abrir ↗Metasploit300
Car Rental System 1.0 File Upload RCE (Authenticated)
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a
28RIESGO
abrir ↗Metasploit300
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RIESGO
abrir ↗Metasploit600
Remote Code Execution Vulnerability in Vvveb
givanz Vvveb Code Editor code.php save code injection
28RIESGO
abrir ↗Metasploit600
Sitecore CVE-2025-27218 BinaryFormatter Deserialization Exploit
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RIESGO
abrir ↗Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
Clinics Patient Management System SQL Injection
43RIESGO
abrir ↗Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
SourceCodester Clinics Patient Management System unrestricted upload
28RIESGO
abrir ↗Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RIESGO
abrir ↗Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
41RIESGO
abrir ↗Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
36RIESGO
abrir ↗Metasploit600
Craft CMS Twig Template Injection RCE via FTP Templates Path
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir ↗Metasploit600
Windows Cloud File Mini Filer Driver Heap Overflow
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.