Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
71.836 exploits
GitHub PoC
CVE-2025-55182 — React2Shell
CVE-2025-55182CRITICALbajo ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Investigating CVE-2022-36804
CVE-2022-36804HIGHbajo ataque24 mar 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-33044CRITICALbajo ataque24 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH24 mar 2026
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 mar 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.
CVE-2012-595823 mar 2026
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir
GitHub PoC
rocket-panda/CVE-2025-9074
CVE-2025-9074CRITICAL23 mar 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir
GitHub PoC
CVE-2018-7422
CVE-2018-742223 mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL23 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-2473MEDIUM23 mar 2026
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RIESGO
abrir
GitHub PoC1
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.
CVE-2025-66398CRITICAL23 mar 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2018-742223 mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
Metasploit300
Citrix ADC (NetScaler) CVE-2026-3055 Scanner
CVE-2026-3055CRITICALbajo ataque23 mar 2026
Insufficient input validation leading to memory overread
95RIESGO
abrir
GitHub PoC
Lỗ hổng CVE-2025-64446 & CVE-2025-58034
CVE-2025-64446CRITICALbajo ataque22 mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC
By PrivacyHunter
CVE-2021-43798HIGHbajo ataque22 mar 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC
폰트 인덱스 처리에서 발생하는 signed overflow 취약점
CVE-2023-21716CRITICAL22 mar 2026
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware22 mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-43798HIGHbajo ataque22 mar 2026
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALbajo ataqueransomware22 mar 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.
CVE-2021-44228CRITICALbajo ataqueransomware22 mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.
CVE-2021-44228CRITICALbajo ataqueransomware22 mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.
CVE-2021-44228CRITICALbajo ataqueransomware22 mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALbajo ataque22 mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC
Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for educational purposes
CVE-2014-0160HIGHbajo ataque22 mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque21 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL21 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque21 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
anteriorpágina 100 / 2395siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.