Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.863exploits catalogados
32.152CVEs con explotación pública
1932probados en laboratorio
13.264 exploits
GitHub PoC
GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)
CVE-2025-68613CRITICALbajo ataque24 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.
CVE-2025-55182CRITICALbajo ataqueransomware24 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC6
RCE exploit PoC for CVE-2025-55182 and CVE-2025-66478 in Next.js and React Server Components with scanner and exploitation tools.
CVE-2025-55182CRITICALbajo ataqueransomware23 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213
CVE-2025-66209CRITICAL23 dic 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
48RIESGO
abrir
GitHub PoC
a controlled environment to test CVE-2025-55182.
CVE-2025-55182CRITICALbajo ataqueransomware23 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.
CVE-2004-268723 dic 2025
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir
GitHub PoC
My poc to exploit this vuln :D
CVE-2025-68613CRITICALbajo ataque23 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.
CVE-2025-68613CRITICALbajo ataque23 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
ali-py3/Exploit-CVE-2025-68613
CVE-2025-68613CRITICALbajo ataque23 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
通过GitHub Copilot 辅助分析CVE-2025-68613漏洞
CVE-2025-68613CRITICALbajo ataque23 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
POC for CVE-2025-68613
CVE-2025-68613CRITICALbajo ataque23 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
nulltrace1336/Samba-Exploit-CVE-2007-2447
CVE-2007-244723 dic 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487
CVE-2023-44487HIGHbajo ataque23 dic 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.
CVE-2021-3493HIGHbajo ataque23 dic 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC146
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
CVE-2025-54068CRITICALbajo ataque23 dic 2025
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC1
js2py sandbox escape to reverse shell
CVE-2024-39205CRITICAL23 dic 2025
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RIESGO
abrir
GitHub PoC
CVE-2025-14558
CVE-2025-14558HIGH23 dic 2025
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
GitHub PoC
machevalia/CVE-2025-14733
CVE-2025-14733CRITICALbajo ataque23 dic 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
83RIESGO
abrir
GitHub PoC2
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
CVE-2025-62215HIGHbajo ataque23 dic 2025
Windows Kernel Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.
CVE-2025-24813CRITICALbajo ataque23 dic 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Spring4Shell
CVE-2022-22965CRITICALbajo ataque22 dic 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC1
Exploit Code for React2Shell RCE vulnerability (CVE-2025-55182) affecting React Server Components 19.0.0-19.2.0. Exploits unsafe deserialization for unauthenticated remote code execution.
CVE-2025-55182CRITICALbajo ataqueransomware22 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.
CVE-2011-252322 dic 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE
CVE-2024-3408CRITICAL22 dic 2025
Authentication Bypass and RCE in man-group/dtale
85RIESGO
abrir
GitHub PoC6
A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.
CVE-2025-68461HIGHbajo ataque22 dic 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RIESGO
abrir
GitHub PoC28
Detection for CVE-2025-68613
CVE-2025-68613CRITICALbajo ataque22 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC25
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.
CVE-2025-68613CRITICALbajo ataque22 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
CVE-2025-68613
CVE-2025-68613CRITICALbajo ataque22 dic 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC10
React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).
CVE-2025-55182CRITICALbajo ataqueransomware22 dic 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
zaydbf/CVE-2025-9074-Poc
CVE-2025-9074CRITICAL22 dic 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.