Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
71.886 exploits
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALbajo ataque07 mar 2026
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque07 mar 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware06 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-21746HIGH06 mar 2026
Windows NTLM Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Full-cycle Pentest on Metasploitable (VMware/Kali). Scanned services (Apache Tomcat/8180), researched CVE-2002-0936 via Exploit-DB, and gained access using default creds (Metasploit). Performed local enumeration for SUID misconfigs, exploiting a legacy Nmap binary to escalate privileges to Root.
CVE-2002-093606 mar 2026
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the w
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-398006 mar 2026
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RIESGO
abrir
GitHub PoC
luoqichen/CVE-2025-55182-POC
CVE-2025-55182CRITICALbajo ataqueransomware06 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque06 mar 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai
CVE-2024-3912CRITICAL06 mar 2026
ASUS Router - Upload arbitrary firmware
48RIESGO
abrir
GitHub PoC
this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452
CVE-2023-3452CRITICAL06 mar 2026
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RIESGO
abrir
GitHub PoC2
yonathanpy/CVE-2025-32462-CVE-2025-32463-PoC-Lab
CVE-2025-32462LOW05 mar 2026
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0185HIGHbajo ataque05 mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
Metasploit600
AVideo Encoder getImage.php Unauthenticated Command Injection
CVE-2026-29058CRITICAL05 mar 2026
AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php
43RIESGO
abrir
Metasploit300
AVideo Unauthenticated SQL Injection Credential Dump
CVE-2026-28501CRITICAL05 mar 2026
WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
43RIESGO
abrir
GitHub PoC
shakyanayann/CVE-2022-0185
CVE-2022-0185HIGHbajo ataque05 mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque05 mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20122MEDIUMbajo ataque04 mar 2026
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
63RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291104 mar 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC
HazaVVIP/CVE-2025-30208
CVE-2025-30208MEDIUM04 mar 2026
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Includes vulnerability breakdown, affected versions, exploitation methodology, and mitigation guidance for research and educational purposes.
CVE-2024-1086HIGHbajo ataqueransomware04 mar 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC1
Faridi-m/CVE-2021-22911-RocketChat
CVE-2021-2291104 mar 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
GitHub PoC
arrhenius975/CVE-2024-38063-Exploit-Refactoring
CVE-2024-38063CRITICAL04 mar 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
prabeershakya/CVE-2022-0185-POC
CVE-2022-0185HIGHbajo ataque04 mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC19
Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)
CVE-2021-33044CRITICALbajo ataque03 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
Exploit-DB
Boss Mini v1.4.0 - Local File Inclusion (LFI)
CVE-2023-3643HIGH03 mar 2026
Boss Mini document file inclusion
78RIESGO
abrir
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque03 mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC1
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome use-after-free vulnerability in the Blink CSS engine.
CVE-2026-2441HIGHbajo ataque03 mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
Exploit-DB
WordPress Backup Migration 1.3.7 - Remote Command Execution
CVE-2023-6553CRITICAL03 mar 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
GitHub PoC
CVE-2025-68613 — n8n RCE via Expression Injection
CVE-2025-68613CRITICALbajo ataque03 mar 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-2961HIGH03 mar 2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
anteriorpágina 108 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.