Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
71.886 exploits
VulnCheck XDB
info-leak
CVE-2023-27163MEDIUM03 feb 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque02 feb 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque02 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
Spydomain/CVE-2017-1000112-PoC
CVE-2017-100011202 feb 2026
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir
GitHub PoC1
Spydomain/CVE-2021-22555-Poc
CVE-2021-22555HIGHbajo ataque02 feb 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC
CVE-2025-32433-available-for-windows
CVE-2025-32433CRITICALbajo ataque02 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC1
thomas-osgood/cve-2025-58360
CVE-2025-58360HIGHbajo ataque02 feb 2026
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
GitHub PoC1
[우리 FISA] 기술 세미나 우승 - 클라우드 서비스 개발 6기 3팀 - React2Shell (CVE-2025-55182) 분석 및 연구
CVE-2025-55182CRITICALbajo ataqueransomware02 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-58360HIGHbajo ataque02 feb 2026
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware02 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque02 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque02 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability
CVE-2025-29927CRITICAL01 feb 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque01 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC3
Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)
CVE-2022-0847HIGHbajo ataque01 feb 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Dirty COW Privilege Escalation (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque01 feb 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL01 feb 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC27
This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive server files via the MediaController. Intended for authorized security auditing and educational research only.
CVE-2024-46987HIGH01 feb 2026
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir
GitHub PoC17
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
CVE-2025-43529HIGHbajo ataque01 feb 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
GitHub PoC1
CVE-2025-40554 Exploitation
CVE-2025-40554CRITICAL31 ene 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RIESGO
abrir
GitHub PoC
Superproject repo for Backup Exec CVE-2024-32002 exploit
CVE-2024-32002CRITICAL31 ene 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque31 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware31 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
React2shell exploit (CVE-2025-55182+CVE-2025-66478)
CVE-2025-55182CRITICALbajo ataqueransomware31 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Superproject repo for Backup Exec CVE-2025-48384 exploit
CVE-2025-48384HIGHbajo ataque31 ene 2026
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-48384HIGHbajo ataque31 ene 2026
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
GitHub PoC
Submodule repo for Backup Exec CVE-2024-32002 exploit
CVE-2024-32002CRITICAL31 ene 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RIESGO
abrir
GitHub PoC
afifudinmtop/CVE-2021-43857-Gerapy-v0.9.7
CVE-2021-43857CRITICAL30 ene 2026
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir
GitHub PoC3
1atakan1/CVE-2025-6934
CVE-2025-6934CRITICAL30 ene 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the Use-After-Free (UAF) in CVE-2025-43529 by desynchronizing the WebKit garbage collector from the GPU's Metal command buffer.
CVE-2025-43529HIGHbajo ataque30 ene 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
anteriorpágina 121 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.