Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
GitHub PoC5
shahidmallaofficial/cpanel-cve-2026-41940-fix
CVE-2026-41940CRITICALbajo ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque30 abr 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-41940利用工具(go并发检测,python利用)
CVE-2026-41940CRITICALbajo ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
rdyprtmx/poc-cve-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
FUXA 1.2.8 - Authentication Bypass + RCE Exploit
CVE-2025-69985CRITICALwebappsmultiple30 abr 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RIESGO
abrir
GitHub PoC11
CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware30 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
Winrar Exploit CVE-2023-38831
CVE-2023-38831HIGHbajo ataqueransomware30 abr 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
Exploit-DB
Erugo 0.2.14 - Remote Code Execution (RCE)
CVE-2026-24897CRITICALwebappsmultiple30 abr 2026
Authenticated Remote Code Execution via Arbitrary File Upload
48RIESGO
abrir
GitHub PoC8
Windows Shell Spoofing Vulnerability
CVE-2026-32202MEDIUMbajo ataque30 abr 2026
Windows Shell Spoofing Vulnerability
75RIESGO
abrir
Exploit-DB
Python-Multipart 0.0.22 - Path Traversal
CVE-2026-24486HIGHwebappspython30 abr 2026
Python-Multipart has Arbitrary File Write via Non-Default Configuration
41RIESGO
abrir
Exploit-DB
Frigate NVR 0.16.3 - Remote Code Execution
CVE-2026-25643CRITICALwebappsmultiple30 abr 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RIESGO
abrir
GitHub PoC
My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.
CVE-2023-46604CRITICALbajo ataqueransomware30 abr 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
solarlynxsqueeze/CVE-2026-32202
CVE-2026-32202MEDIUMbajo ataque30 abr 2026
Windows Shell Spoofing Vulnerability
75RIESGO
abrir
Exploit-DB
HAX CMS 24.x - Stored Cross-Site Scripting (XSS)
CVE-2026-22704HIGHwebappsmultiple29 abr 2026
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
41RIESGO
abrir
Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.
CVE-2024-8503CRITICAL29 abr 2026
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir
Exploit-DB
GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
CVE-2026-22241HIGHwebappsmultiple29 abr 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RIESGO
abrir
Exploit-DB
phpMyFAQ 4.0.16 - Improper Authorization
CVE-2026-24421MEDIUMwebappsphp29 abr 2026
phpMyFAQ missing authorization exposes /api/setup/backup to any authenticated user
33RIESGO
abrir
Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
CVE-2026-34197HIGHbajo ataque29 abr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
Exploit-DB
GeographicLib v2.5.1 - stack buffer overflow
CVE-2025-60751HIGHwebappsmultiple29 abr 2026
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RIESGO
abrir
GitHub PoC3
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).
CVE-2026-42167HIGH29 abr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
Exploit-DB
GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
CVE-2026-24061CRITICALbajo ataquelocallinux29 abr 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC7
Post-Exploitation Session Validation Tool for CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware29 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
LangChain Core 1.2.4 - SSTI/RCE
CVE-2025-68664CRITICALwebappsmultiple29 abr 2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
60RIESGO
abrir
GitHub PoC
Wise-Security/CVE-2026-38945
CVE-2026-38945HIGH29 abr 2026
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod
41RIESGO
abrir
GitHub PoC26
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
CVE-2026-41940CRITICALbajo ataqueransomware29 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware29 abr 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
Exploit-DB
Atlona ATOMERX21 - Authenticated Command Injection
CVE-2024-30167MEDIUMlocalmultiple29 abr 2026
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm
33RIESGO
abrir
Exploit-DB
Fedora - Local Privilege Escalation
CVE-2025-12744HIGHlocallinux29 abr 2026
Abrt: command-injection in abrt leading to local privilege escalation
41RIESGO
abrir
GitHub PoC1
Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)
CVE-2024-4577CRITICALbajo ataqueransomware29 abr 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
anteriorpágina 153 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.