Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.941exploits catalogados
32.192CVEs con explotación pública
1932probados en laboratorio
71.943 exploits
GitHub PoC1
Final Project in Fundamental network security,POC CVE-202438063
CVE-2024-38063CRITICAL21 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL21 ene 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RIESGO
abrir
VulnCheck XDB
local
CVE-2023-52271MEDIUM21 ene 2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-61686CRITICAL21 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
afifudinmtop/CVE-2021-21425
CVE-2021-21425CRITICAL21 ene 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC1
InfoSecAntara/CVE-2025-14847-MongoDB
CVE-2025-14847HIGHbajo ataque21 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware21 ene 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.
CVE-2025-14847HIGHbajo ataque20 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL20 ene 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque20 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 ene 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 ene 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
GitHub PoC
CVE-2025-55182(命令执行、反弹shell、注入内存马)
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
CVE-2026-23744CRITICAL20 ene 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.
CVE-2022-22965CRITICALbajo ataque20 ene 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.
CVE-2011-252320 ene 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALbajo ataque20 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC5
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
CVE-2025-54068CRITICALbajo ataque20 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC
SSP H3
CVE-2024-38063CRITICAL20 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
dragosbanica/CVE-2023-0386_POC
CVE-2023-0386HIGHbajo ataque20 ene 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
Cacti exploit
CVE-2024-25641CRITICAL20 ene 2026
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
VulnCheck XDB
local
CVE-2023-0386HIGHbajo ataque20 ene 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir
GitHub PoC
ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab
CVE-2024-21413CRITICALbajo ataque19 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-20805MEDIUMbajo ataque19 ene 2026
Desktop Window Manager Information Disclosure Vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware19 ene 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
CVE-2023-0214MEDIUM19 ene 2026
XSS in Skyhigh Security SWG
33RIESGO
abrir
GitHub PoC
Killian0713/Assignement_3-CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque19 ene 2026
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
anteriorpágina 127 / 2399siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.