Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC
rmhowe425/POC-CVE-2026-19286
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RIESGO
abrir ↗GitHub PoC
rmhowe425/POC-CVE-2026-18729
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
41RIESGO
abrir ↗GitHub PoC
FranklinF25/cve-2026-42533
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir ↗GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir ↗GitHub PoC
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
gpt-crawler Arbitrary File Write via outputFileName Parameter
41RIESGO
abrir ↗GitHub PoC★ 2
Learn how I found my first two CVEs by pure accident.
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RIESGO
abrir ↗GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RIESGO
abrir ↗GitHub PoC
Hunt-Benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
48RIESGO
abrir ↗GitHub PoC★ 4
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PaperCut MF/NG: Authentication Bypass
86RIESGO
abrir ↗GitHub PoC★ 2
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PaperCut MF/NG: Authentication Bypass
86RIESGO
abrir ↗GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗GitHub PoC
CVE-2026-33017 PoC Reverse Shell
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RIESGO
abrir ↗GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗GitHub PoC
CVE-2026-66384 - Draft or TODO
Authenticated users may write data outside the intended Docker cache path
63RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
info-leak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
Hari-v542/CVE-2026-52923
ipc: limit next_id allocation to the valid ID range
41RIESGO
abrir ↗GitHub PoC
Testing CVE-2026-70463 by Fyyre
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.