Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
13.264 exploits
GitHub PoC
Test
CVE-2025-48384HIGHbajo ataque14 dic 2025
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Étude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé et une proposition de mise à jour de PSSI. Pour un objectif de TP
CVE-2021-44228CRITICALbajo ataqueransomware14 dic 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC35
A CVE-2025-55182(React2Shell) Toolbox Application
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Example web application that run on struts2 REST plugin 2.5.8, for demonstration purpose only
CVE-2017-9805HIGHbajo ataque13 dic 2025
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC1
CVE-2024-27348 Exploitation Toolkit: Complete RCE exploit for Apache Huge-Graph-Server vulnerability.
CVE-2024-27348CRITICALbajo ataque13 dic 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
High-performance Go implementation for detecting React Server Components RCE vulnerabilities (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC6
Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE). Includes detailed vulnerability analysis, exploitation techniques, and team learning materials.
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code execution (RCE) on vulnerable servers.
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Analysis, Validation Environment, and POC for CVE-225-55182 Vulnerability.
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
A research report on CVE-2025-55182 (React2Shell).
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
A hands-on lab for understanding and exploiting CVE-2025-55182 (React2Shell) - Remote Code Execution in React Server Components
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
ZorvithonLeo-Null/CVE-2025-55182-exploit
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
NodeJS-based exploit script and scanner for the React Server Components "React2Shell" vulnerability (CVE-2025-55182).
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
A hybrid security scanner for detecting CVE-2025-55182 in Next.js and Waku applications. Features combined static code analysis and safe dynamic verification for DevSecOps workflows.
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Check if your server is affected by CVE-2025-55182 & CVE-2025-66478
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
grejh0t/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
A modern Next.js vulnerable web app themed as a news / blog portal for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) to learn, detect, and safely exercise React2Shell. Runs unpatched React 19.0.0 and Next.js 15.0.3.
CVE-2025-55182CRITICALbajo ataqueransomware13 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC27
CVE-2025-8110 PoC
CVE-2025-8110HIGHbajo ataque13 dic 2025
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
PoC para explotar el CVE-2024-10914
CVE-2024-10914CRITICAL13 dic 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
Joker-Wiggin/CVE-2025-58360-GeoServer-XXE
CVE-2025-58360HIGHbajo ataque12 dic 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
Python port of an ExploitDB proof-of-concept.
CVE-2019-11043HIGHbajo ataqueransomware12 dic 2025
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
python script to exploit Joomla 3.7
CVE-2017-891712 dic 2025
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC
Passive detection for CVE-2025-58360
CVE-2025-58360HIGHbajo ataque12 dic 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC
Exploit for CVE-2025-11001
CVE-2025-11001HIGH12 dic 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
GitHub PoC46
Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
CVE-2025-55182 – CVE-2025-66478 – React2Shell
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
yuta3003/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
POC React2Shell-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
CVE-2025-55182 payload
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC5
WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using React Server Components. Designed for CTFs and research, it features a single-command mode, an interactive web CLI, and reverse shell capabilities to demonstrate RCE.
CVE-2025-55182CRITICALbajo ataqueransomware12 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.