Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
71.886 exploits
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque30 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC3
1atakan1/CVE-2025-6934
CVE-2025-6934CRITICAL30 ene 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RIESGO
abrir
GitHub PoC1
imbas007/auth-bypass-CVE-2025-40554
CVE-2025-40554CRITICAL29 ene 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RIESGO
abrir
GitHub PoC
HP Power Manager 4.2 (Build 7) exploit
CVE-2009-399929 ene 2026
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-5419HIGHbajo ataque29 ene 2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RIESGO
abrir
GitHub PoC
CVE-2020-11107-Local-Privilege-Escalation-XAMPP-7.2.29-7.3.x-7.3.16-7.4.x-7.4.4
CVE-2020-1110729 ene 2026
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-40554CRITICAL29 ene 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RIESGO
abrir
GitHub PoC
Metasploitable 2 üzerinde vsftpd 2.3.4 (CVE-2011-2523) zafiyetinin istismarı ve sızma sonrası adımlarını içeren laboratuvar çalışması.
CVE-2011-252329 ene 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
Proof of concept for CVE-2019-11707
CVE-2019-11707HIGHbajo ataque29 ene 2026
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC30
An uninitialized read vulnerability by incorrect Turboshaft Store-Store Elimination in V8.
CVE-2025-5419HIGHbajo ataque29 ene 2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RIESGO
abrir
GitHub PoC
deepankarkumar1/CVE-2025-55182_Vulnerable-Application
CVE-2025-55182CRITICALbajo ataqueransomware29 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
Metasploit600
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
CVE-2026-1340CRITICALbajo ataque29 ene 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
Metasploit600
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
CVE-2026-1281CRITICALbajo ataque29 ene 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
Metasploit600
Tactical RMM Jinja2 SSTI Remote Code Execution
CVE-2025-69516HIGH29 ene 2026
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica
36RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11707HIGHbajo ataque29 ene 2026
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-2449928 ene 2026
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40551CRITICALbajo ataque28 ene 2026
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
95RIESGO
abrir
GitHub PoC
CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that affected hundreds of thousands of organizations worldwide.
CVE-2021-26855CRITICALbajo ataqueransomware28 ene 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map, reconstruct, and extract specific memory regions across time, not just adjacent buffers.
CVE-2014-0160HIGHbajo ataque28 ene 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
22imer/CVE-2014-0160
CVE-2014-0160HIGHbajo ataque28 ene 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
CVE-2025-43529HIGHbajo ataque28 ene 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40536HIGHbajo ataque28 ene 2026
SolarWinds Web Help Desk Security Control Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque28 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque28 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2017-7921CRITICALbajo ataque28 ene 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC5
用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。
CVE-2017-7921CRITICALbajo ataque28 ene 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL28 ene 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RIESGO
abrir
GitHub PoC
Clarification Regarding the Rejection Arguments
CVE-2025-56005CRITICAL28 ene 2026
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
53RIESGO
abrir
GitHub PoC
Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.
CVE-2022-0847HIGHbajo ataque28 ene 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-2449928 ene 2026
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RIESGO
abrir
anteriorpágina 122 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.