Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.901exploits catalogados
32.161CVEs con explotación pública
1932probados en laboratorio
71.901 exploits
VulnCheck XDB
initial-access
CVE-2023-51409CRITICAL22 ene 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RIESGO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
CVE-2024-51793CRITICAL22 ene 2026
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-61686CRITICAL21 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
SMBv1: CVE-2017-0143, gravedad 8.8, de ejecucion remota de codigo (RCE), en Windows con SMBv1 (ms17-010)
CVE-2017-0143HIGHbajo ataqueransomware21 ene 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
afifudinmtop/CVE-2021-21425
CVE-2021-21425CRITICAL21 ene 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware21 ene 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Final Project in Fundamental network security,POC CVE-202438063
CVE-2024-38063CRITICAL21 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC1
InfoSecAntara/CVE-2025-14847-MongoDB
CVE-2025-14847HIGHbajo ataque21 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-9193-Postgresql-RCE
CVE-2019-919321 ene 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALbajo ataque21 ene 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-52271MEDIUM21 ene 2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL21 ene 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919321 ene 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
CVE-2024-38476CRITICAL21 ene 2026
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RIESGO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
CVE-2019-10149CRITICALbajo ataque21 ene 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC2
This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771
CVE-2025-7771HIGH21 ene 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2017-7921CRITICALbajo ataque21 ene 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC
MOVEit Transfer 2023 mass data breach (CVE-2023-34362)
CVE-2023-34362CRITICALbajo ataqueransomware21 ene 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC2
海康威视RCE漏洞 批量检测和利用工具
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.
CVE-2022-22965CRITICALbajo ataque20 ene 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
CVE-2025-55182(命令执行、反弹shell、注入内存马)
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALbajo ataque20 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque20 ene 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL20 ene 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 ene 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 ene 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
anteriorpágina 126 / 2397siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.