Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.329exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.482VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3489 exploits
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RIESGO
abrir ↗Metasploit600
Tenable Security Center SCAP Audit File Command Injection
Command Injection
63RIESGO
abrir ↗Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
# Active Storage allowed transformation methods potentially unsafe
Active Storage attempts to prevent the use of pote
63RIESGO
abrir ↗Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir ↗Metasploit600
JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RIESGO
abrir ↗Metasploit600
Check Point SmartConsole Authentication Bypass Run Script RCE
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir ↗Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗Metasploit600
Langflow AI auto_login RCE
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir ↗Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗Metasploit600
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir ↗Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RIESGO
abrir ↗Metasploit600
Flowise MCP Server Remote Code Execution
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
36RIESGO
abrir ↗Metasploit600
Joomla Content Editor Unauthenticated File Upload RCE
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗Metasploit500
HP Poly Voice Unauthenticated Remote Code Execution
Poly Voice – Possible Remote Control of Certain Poly Devices
55RIESGO
abrir ↗Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RIESGO
abrir ↗Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RIESGO
abrir ↗Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗Metasploit300
Linux Kernel __ptrace_may_access() Exit Race chage File Disclosure
ptrace: slightly saner 'get_dumpable()' logic
56RIESGO
abrir ↗Metasploit500
Fragnesia LPE (CVE-2026-46300)
net: skbuff: preserve shared-frag marker during coalescing
56RIESGO
abrir ↗Metasploit400
xfrm-ESP Page-Cache Write via CVE-2026-43284
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗Metasploit400
rxkad Page-Cache Write via CVE-2026-43500
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RIESGO
abrir ↗Metasploit600
Dalfox Found-Action Deserialization RCE
Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
48RIESGO
abrir ↗Metasploit300
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir ↗Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir ↗Metasploit600
cPanel/WHM CRLF Injection Authentication Bypass RCE
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗Metasploit600
OpenCATS Installer PHP Code Injection
OpenCATS PHP Code Injection via installer AJAX endpoint
75RIESGO
abrir ↗página 1 / 117siguiente →
Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.