Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
GitHub PoC
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
MindsDB 25.9.1.1 - Path Traversal
CVE-2026-27483HIGHwebappsmultiple04 may 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RIESGO
abrir
GitHub PoC1
rootdirective-sec/CVE-2026-39987-Lab
CVE-2026-39987CRITICALbajo ataque04 may 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
This repository contains a Python verification script for `CVE-2026-41940`, a critical authentication bypass vulnerability disclosed in cPanel & WHM. > This project is intended for authorized defensive validation only. It is not intended for exploit development, unauthorized access, or misuse against systems you do not own or administer.
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)
CVE-2025-60690HIGHhardwaremultiple04 may 2026
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
Linux nf_tables 6.19.3 - Local Privilege Escalation
CVE-2026-23231HIGHlocallinux04 may 2026
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-69985CRITICAL04 may 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RIESGO
abrir
Exploit-DB
Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation
CVE-2025-40271HIGHlocallinux04 may 2026
fs/proc: fix uaf in proc_readdir_de()
41RIESGO
abrir
GitHub PoC
kaleth4/CVE-2025-60751
CVE-2025-60751HIGH04 may 2026
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RIESGO
abrir
GitHub PoC
Mrhudson69/cve-2026-31431
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42167HIGH04 may 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque04 may 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
Exploit CVE-2026-41940 auto exploit
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2
CVE-2011-252304 may 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
kaleth4/CVE-2026-42167
CVE-2026-42167HIGH04 may 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
GitHub PoC
kaleth4/CVE-2025-47987
CVE-2025-47987HIGH04 may 2026
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware04 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque03 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
imbas007/POC_CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware03 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
anteriorpágina 144 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.