Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
GitHub PoC
CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware06 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
Analysis of network scan results, service vulnerabilities, OS fingerprinting, and critical Nessus findings including Ghostcat (CVE-2020-1938).
CVE-2020-1938CRITICALbajo ataque06 may 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC8
Apache HTTP/2 double-free vulnerability PoC (CVE-2026-23918)
CVE-2026-23918HIGH06 may 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RIESGO
abrir
GitHub PoC1
Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.
CVE-2026-41940CRITICALbajo ataqueransomware06 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC2
CVE-2026-40776 — Broken Access Control + IDOR in WordPress Eventin (wp-event-solution) <= 4.1.8
CVE-2026-40776HIGH06 may 2026
WordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability
41RIESGO
abrir
GitHub PoC
MartinaStarone/CVE-2026-2441
CVE-2026-2441HIGHbajo ataque06 may 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-4040CRITICALbajo ataque06 may 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC1
Zimbra Path Traversal (CVE-2025-68645) - Unauthenticated file read vulnerability in Zimbra Collaboration Suite
CVE-2025-68645HIGHbajo ataque06 may 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir
GitHub PoC
This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer application, a widely used enterprise Managed File Transfer (MFT) platform. The project was developed as part of the CYB625 – Ethical Hacking & Penetration Testing course at Pace University.
CVE-2023-34362CRITICALbajo ataqueransomware06 may 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC3
Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.
CVE-2026-31431HIGHbajo ataque06 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
Proof-of-concept for CVE-2024-4040 (CrushFTP SSTI -> unauthenticated LFI) in a controlled CS443 lab environment - for educational/authorised use only.
CVE-2024-4040CRITICALbajo ataque06 may 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2024-22120 that leverages time-based SQL injection and gopher-based SSRF to achieve remote code execution on vulnerable Zabbix servers for educational security research.
CVE-2024-22120CRITICAL06 may 2026
Time Based SQL Injection in Zabbix Server Audit Log
70RIESGO
abrir
GitHub PoC
roodhelios/CVE-2022-26134-OGNL-Injection
CVE-2022-26134CRITICALbajo ataqueransomware06 may 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
cPanel/WHM CVE-2026-41940 CRLF injection auth bypass exploit
CVE-2026-41940CRITICALbajo ataqueransomware05 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
ZildanZ/CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware05 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
Upgrade to Apache 2.4.67 to fix CVE-2026-23918 vulneribility
CVE-2026-23918HIGH05 may 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RIESGO
abrir
GitHub PoC
Passive HTTP metadata auditor for CVE-2026-23918 exposure triage
CVE-2026-23918HIGH05 may 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RIESGO
abrir
GitHub PoC4
This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66 `mod_http2`.
CVE-2026-23918HIGH05 may 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RIESGO
abrir
GitHub PoC
Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico
CVE-2021-44228CRITICALbajo ataqueransomware05 may 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico
CVE-2014-6271CRITICALbajo ataque05 may 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-7482HIGH05 may 2026
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware05 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.
CVE-2026-31431HIGHbajo ataque05 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque05 may 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
Analysis of CVE-2026-24072
CVE-2026-24072HIGH05 may 2026
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
21RIESGO
abrir
GitHub PoC1
Утилита для Linux, которая проверяет доступность `AF_ALG`/`algif_aead` и помогает оценить риск по `CVE-2026-31431`.
CVE-2026-31431HIGHbajo ataque05 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware05 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHbajo ataque05 may 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
One IPv6 ND option with length zero. One missing check. Daemon walks backward and lives in the loop. Reported to OpenBSD, fixed, CVE assigned.
CVE-2026-41285MEDIUM05 may 2026
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis
13RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque05 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
anteriorpágina 142 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.