Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
71.886 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL13 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL13 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque13 abr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware13 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used Perl's POSIX setuid(0) to escalate to root → read /root/flag.txt
CVE-2025-55182CRITICALbajo ataqueransomware13 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Fork of gogs/gogs for reachability benchmark testing (CVE-2024-45337)
CVE-2024-45337CRITICAL13 abr 2026
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RIESGO
abrir
GitHub PoC
DonVorrin/CVE-2023-29357
CVE-2023-29357CRITICALbajo ataqueransomware13 abr 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
This is a special panel that is used to send POC requests with the output of responses.
CVE-2025-55182CRITICALbajo ataqueransomware13 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALbajo ataqueransomware13 abr 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-8110HIGHbajo ataque13 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque12 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-8110HIGHbajo ataque12 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions
CVE-2025-55182CRITICALbajo ataqueransomware12 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
CVE-2025-58434 and CVE-2025-59528 chain POC
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC
Found 200+ vulnerabilities on scanme.nmap.org including CVE-2023-38408 (9.8 critical)
CVE-2023-38408CRITICAL12 abr 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC1
kartik2005221/CVE-2025-58434-poc
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC1
RCE exploit for Gogs <= 0.13.3
CVE-2025-8110HIGHbajo ataque12 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
CVE-2025-58434 PoC
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC2
Exploitation Silentium HTB-CTF
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC
CVE-2025-58434 & CVE-2025-59528
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC1
Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)
CVE-2025-58434CRITICAL12 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
Security research and CVE write-ups by Steven Amador (HackinKraken) - CVE-2022-2650, CVE-2026-39338
CVE-2026-39338HIGH12 abr 2026
ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL12 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque11 abr 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing
CVE-2025-69212CRITICAL11 abr 2026
OpenSTAManager has an OS Command Injection in P7M File Processing
48RIESGO
abrir
GitHub PoC
Real-world incident response for CVE-2025-55182 (React2Shell) — script injection, server remediation, and post-incident report
CVE-2025-55182CRITICALbajo ataqueransomware11 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
Kouf320/docker-lab-cve-2017-5638-cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware11 abr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
anteriorpágina 92 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.