Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3489 exploits
Metasploit600
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
CVE-2026-1340CRITICALbajo ataque29 ene 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40536HIGHbajo ataque28 ene 2026
SolarWinds Web Help Desk Security Control Bypass Vulnerability
100RIESGO
abrir
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40551CRITICALbajo ataque28 ene 2026
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
95RIESGO
abrir
Metasploit500
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque26 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
Metasploit500
HUSTOJ Admin users can zip-slip problem_import_qduoj.php, planting PHP files in webroot for RCE
CVE-2026-24479CRITICAL26 ene 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RIESGO
abrir
Metasploit300
osTicket Arbitrary File Read via PHP Filter Chains in mPDF
CVE-2026-22200HIGH13 ene 2026
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
58RIESGO
abrir
Metasploit300
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVE-2025-14847HIGHbajo ataque19 dic 2025
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34442MEDIUM19 dic 2025
AVideo < 20.1 System Path Disclosure via Public API
28RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34441MEDIUM19 dic 2025
AVideo < 20.1 User Information Disclosure via Public API
28RIESGO
abrir
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34433CRITICAL19 dic 2025
AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
63RIESGO
abrir
Metasploit600
ChurchCRM Unauthenticated RCE via Setup Page
CVE-2025-62521CRITICAL17 dic 2025
ChurchCRM has unauthenticated RCE in its Install Wizard
43RIESGO
abrir
Metasploit300
ChurchCRM Database Restore RCE 6.2.0
CVE-2025-68109CRITICAL17 dic 2025
ChurchCRM vulnerable to RCE with database restore functionality
43RIESGO
abrir
Metasploit600
Control Web Panel /admin/index.php Unauthenticated RCE
CVE-2025-67888HIGH16 dic 2025
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RIESGO
abrir
Metasploit600
HPE OneView unauthenticated RCE
CVE-2025-37164CRITICALbajo ataque16 dic 2025
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
Metasploit600
FreeBSD rtsold/rtsol DNSSL Command Injection
CVE-2025-14558HIGH16 dic 2025
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RIESGO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-61675HIGH11 dic 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RIESGO
abrir
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit600
FreePBX firmware file upload
CVE-2025-66039CRITICAL11 dic 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RIESGO
abrir
Metasploit300
Gladinet CentreStack/Triofox Access Ticket Forge
CVE-2025-14611HIGHbajo ataque10 dic 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-6647803 dic 2025
15RIESGO
abrir
Metasploit600
Unauthenticated RCE in React Server Components (React2Shell)
CVE-2025-55182CRITICALbajo ataqueransomware03 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
CVE-2025-13486CRITICAL02 dic 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
75RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66301HIGH01 dic 2025
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RIESGO
abrir
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66294HIGH01 dic 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RIESGO
abrir
Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
CVE-2025-12548CRITICAL01 dic 2025
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RIESGO
abrir
Metasploit300
GeoServer WMS GetMap XXE Arbitrary File Read
CVE-2025-58360HIGHbajo ataque25 nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-11700HIGH17 nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.