Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
GitHub PoC★ 1
CVE-2025-48595 - Draft
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RIESGO
abrir ↗GitHub PoC★ 1
Add go CVE-2026-43284 / CVE-2026-43500 (dirtyfrag) local privilege escalation exploit
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗GitHub PoC
Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Saku0512/CVE-2026-54088-poc
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
48RIESGO
abrir ↗GitHub PoC
lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir ↗GitHub PoC
PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC
leehunkoo/hk_CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗GitHub PoC★ 13
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC★ 47
CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM
Microsoft Install Service Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 1
Rocket.Chat OAuth2 NoSQL Injection
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC★ 6
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir ↗GitHub PoC
DanieleGiovanardi2408/cve-2024-36401-geoserver-rce
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC★ 1
Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗GitHub PoC
这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir ↗VulnCheck XDB
initial-access
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RIESGO
abrir ↗GitHub PoC
lorenzocamilli/CVE-2026-45332-PoC
Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
56RIESGO
abrir ↗GitHub PoC
Performed a Full & Fast vulnerability assessment using OpenVAS against Metasploitable2, identified the critical vsftpd Backdoor vulnerability (CVE-2011-2523), and developed containment, remediation, and incident response documentation.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC
entr0pie/demo-cve-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗GitHub PoC★ 3
Reproducible Docker lab for CVE-2024-21182 — Oracle WebLogic T3/IIOP OpaqueReference JNDI injection → unauthenticated RCE (CVE-2023-21839 patch-bypass family). One-command validate.sh.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗GitHub PoC
CVE-2026-31525 - Draft
bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
41RIESGO
abrir ↗GitHub PoC
jenniferreire26/CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗GitHub PoC
Mender Server - Authenticated Path Traversal to RCE
Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir ↗GitHub PoC
"A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors."
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.