Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.096 exploits
GitHub PoC
CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC
Jeanback1/CVE-2019-0211-exploit
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir ↗GitHub PoC★ 1
SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗VulnCheck XDB
initial-access
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir ↗GitHub PoC
kavin-jindal/CVE-2026-48800-PoC
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
41RIESGO
abrir ↗VulnCheck XDB
info-leak
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RIESGO
abrir ↗VulnCheck XDB
local
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC★ 2
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions ≤ 1.5.0).
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗GitHub PoC
b1nhack/CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir ↗GitHub PoC
CVE-2026-39987 - Draft
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗GitHub PoC
CVE-2025-5947 WordPress Service Finder Bookings ≤ 6.0 Exploit
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RIESGO
abrir ↗GitHub PoC★ 7
Notepad++ RCE via config.xml commandLineInterpreter
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
41RIESGO
abrir ↗GitHub PoC★ 1
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RIESGO
abrir ↗GitHub PoC
PHP poc, exploit for CVE-2025-9074
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RIESGO
abrir ↗GitHub PoC★ 2
Exploiting heap-based buffer overflow in sudo for privilege escalation
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir ↗GitHub PoC
CVE-2026-0257 - PAN-OS
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir ↗GitHub PoC
CVE-2025-10162 Exploit
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RIESGO
abrir ↗GitHub PoC
kavin-jindal/CVE-2026-48778-PoC
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
41RIESGO
abrir ↗GitHub PoC
The ACCSvc service creates a Named Pipe with a weak Security Descriptor that allows any authenticated user to connect and send messages. When a specially crafted message (message type 0x03) is sent to the pipe, the service crashes with exit code 1067 (ERROR_PROCESS_ABORTED).
Acer Care Center creates a Named Pipe with a weak Security Descriptor
33RIESGO
abrir ↗GitHub PoC
HAERIN-L/poc_cve-2026-42208
LiteLLM: SQL injection in Proxy API key verification
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RIESGO
abrir ↗GitHub PoC
SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
33RIESGO
abrir ↗GitHub PoC
Dungsocool/CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.