Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
71.957 exploits
GitHub PoC
dkq-k/cve-2023-22515-1
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verifies exploitation by probing sensitive files. Built for learning CVE analysis, not mass exploitation.
CVE-2021-41773HIGHbajo ataqueransomware16 ene 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)
CVE-2026-46368HIGH16 ene 2026
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC2
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
CVE-2025-59287CRITICALbajo ataque16 ene 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Kai-One001/React-Router-CVE-2025-61686-
CVE-2025-61686CRITICAL16 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
dkq-k/CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.
CVE-2007-244716 ene 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known post-exploitation IOCs.
CVE-2025-20393CRITICALbajo ataque16 ene 2026
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RIESGO
abrir
GitHub PoC
End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment
CVE-2013-3900MEDIUMbajo ataque16 ene 2026
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC1
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).
CVE-2018-011416 ene 2026
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
faisha1311/React2Shell-CVE-2025-55182-TryHackMe
CVE-2025-55182CRITICALbajo ataqueransomware16 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque16 ene 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
A stored Cross‑Site Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized URL‑encoded JavaScript. The payload is stored and later executed in users’ browsers, lead unauthorized actions.
CVE-2026-26719MEDIUM15 ene 2026
Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque15 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC2
WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型的场景下,攻击者可利用此漏洞绕过访问控制、获取敏感数据或实现代码执行。
CVE-2025-14502CRITICAL15 ene 2026
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
48RIESGO
abrir
GitHub PoC
BOSE122/CVE-2024-3094
CVE-2024-3094CRITICAL15 ene 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
CVE-2025-14847HIGHbajo ataque15 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
shubtheone/CVE-2021-36260-hikvision
CVE-2021-36260CRITICALbajo ataque15 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALbajo ataque15 ene 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC
CVE-2025-61686复现的dockerfile与poc
CVE-2025-61686CRITICAL15 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to execute arbitrary OS commands via a malicious POST request.
CVE-2025-11953CRITICALbajo ataque15 ene 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC1
Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and vulnerable behaviors ethically.
CVE-2025-64155CRITICAL15 ene 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RIESGO
abrir
GitHub PoC2
Phantom Signature Attack: An Analysis of the Critical Vulnerability CVE-2025-29774 in the Bitcoin Protocol, SIGHASH_SINGLE Implementation Flaws, and the Mathematical Framework for Private Key Recovery in Lost Cryptocurrency Wallets Enabling Unrestricted Control over BTC Assets
CVE-2025-29774CRITICAL15 ene 2026
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RIESGO
abrir
GitHub PoC
beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560
CVE-2021-3560HIGHbajo ataque14 ene 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2021-44228CRITICALbajo ataqueransomware14 ene 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
encikayelwhitehat-glitch/CVE-2024-3094
CVE-2024-3094CRITICAL14 ene 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2025-9501
CVE-2025-9501CRITICAL14 ene 2026
W3 Total Cache < 2.8.13 - Unauthenticated Command Injection
53RIESGO
abrir
GitHub PoC
🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently.
CVE-2025-14847HIGHbajo ataque14 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
anteriorpágina 129 / 2399siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.