Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
71.886 exploits
VulnCheck XDB
remote-with-credentials
CVE-2024-21413CRITICALbajo ataque25 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque25 ene 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHbajo ataqueransomware25 ene 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque25 ene 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-33044CRITICALbajo ataque25 ene 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 ene 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RIESGO
abrir
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 ene 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 ene 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RIESGO
abrir
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMbajo ataque25 ene 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque25 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-2291HIGHbajo ataqueransomware25 ene 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL25 ene 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20045HIGHbajo ataque25 ene 2026
Cisco Unified Communications Products Remote Code Execution Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL25 ene 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMbajo ataque25 ene 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALbajo ataque25 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALbajo ataque25 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque25 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALbajo ataque24 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-24061CRITICALbajo ataque24 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALbajo ataque24 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque24 ene 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-38408CRITICAL24 ene 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHbajo ataque24 ene 2026
SSRF in adminer
100RIESGO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 ene 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 ene 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware24 ene 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-42013CRITICALbajo ataqueransomware24 ene 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-23760CRITICALbajo ataqueransomware23 ene 2026
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2294CRITICAL23 ene 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
anteriorpágina 124 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.