Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3489 exploits
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
N-central Multiple XXE Injection Vulnerabilities
68RIESGO
abrir ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗Metasploit300
Fortinet FortiWeb create new local admin
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir ↗Metasploit600
FreePBX filestore authenticated command injection
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RIESGO
abrir ↗Metasploit600
Monsta FTP downloadFile Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RIESGO
abrir ↗Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RIESGO
abrir ↗Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
Taiga Authenticated Remote Code Execution
43RIESGO
abrir ↗Metasploit600
Magento SessionReaper
Adobe Commerce | Improper Input Validation (CWE-20)
100RIESGO
abrir ↗Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir ↗Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
Upload Arbitrary Files
100RIESGO
abrir ↗Metasploit600
Oracle E-Business Suite CVE-2025-61882 RCE
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir ↗Metasploit600
Centreon authenticated command injection leading to RCE via broker engine "reload" parameter
RCE via the poller reload feature available only to user with high privilege
41RIESGO
abrir ↗Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir ↗Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Argument Injection Vulnerability in CommServe
33RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Path Traversal Vulnerability
41RIESGO
abrir ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Unauthorized API Access Risk
28RIESGO
abrir ↗Metasploit600
Flowise Custom MCP Remote Code Execution
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RIESGO
abrir ↗Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir ↗Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RIESGO
abrir ↗Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir ↗Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RIESGO
abrir ↗Metasploit600
PivotX Remote Code Execution
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
50RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Remote Code Execution Vulnerability
88RIESGO
abrir ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.