Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware29 abr 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
Exploit-DB
GeographicLib v2.5.1 - stack buffer overflow
CVE-2025-60751HIGHwebappsmultiple29 abr 2026
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-8503CRITICAL29 abr 2026
VICIdial Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC
Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.
CVE-2011-252329 abr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Exploit-DB
Xibo CMS 4.3.0 - RCE via SSTI
CVE-2025-62639webappsmultiple29 abr 2026
20RIESGO
abrir
Exploit-DB
FacturaScripts 2025.43 - XSS
CVE-2025-69210LOWwebappsmultiple29 abr 2026
FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
28RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC434
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque29 abr 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware28 abr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Metasploit600
OpenCATS Installer PHP Code Injection
CVE-2026-27760CRITICAL28 abr 2026
OpenCATS PHP Code Injection via installer AJAX endpoint
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware28 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Esta falla permite a un atacante remoto y sin ningún tipo de autenticación acceder directamente a los tickets de soporte, casos internos y a todos sus archivos adjuntos confidenciales. Al iterar y descargar de forma automatizada los registros de Aranda, dejando la información sensible expuesta a una exfiltración masiva.
CVE-2025-67223HIGH28 abr 2026
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs w
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42208CRITICALbajo ataque28 abr 2026
LiteLLM: SQL injection in Proxy API key verification
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42167HIGH28 abr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56537
CVE-2025-56537MEDIUM28 abr 2026
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute
33RIESGO
abrir
GitHub PoC1
POC for CVE-2026-39816 which allows NiFi users without execute code permissions to run arbitrary scripts
CVE-2026-39816HIGH28 abr 2026
Apache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
21RIESGO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56534
CVE-2025-56534MEDIUM28 abr 2026
A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t
33RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.
CVE-2021-44228CRITICALbajo ataqueransomware28 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC24
POCs to demonstrate CVE-2026-42167 in ProFTPD
CVE-2026-42167HIGH28 abr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
Metasploit600
cPanel/WHM CRLF Injection Authentication Bypass RCE
CVE-2026-41940CRITICALbajo ataqueransomware28 abr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56535
CVE-2025-56535MEDIUM28 abr 2026
A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or
33RIESGO
abrir
GitHub PoC7
Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.
CVE-2024-51482CRITICAL28 abr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RIESGO
abrir
GitHub PoC
MarkArtamonov/OpenNebula-CVE-2025-56536
CVE-2025-56536MEDIUM28 abr 2026
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri
33RIESGO
abrir
GitHub PoC
B1gN0Se/PwnKit_CVE-2021-4034
CVE-2021-4034HIGHbajo ataqueransomware28 abr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Multiple CVEs (CVE-2026-38934, CVE-2026-38935, CVE-2026-38936) discovered in diskover-community including CSRF and XSS vulnerabilities with proof-of-concept and impact analysis.
CVE-2026-38934HIGH27 abr 2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker
41RIESGO
abrir
GitHub PoC
kaleth4/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware27 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.
CVE-2018-14847CRITICALbajo ataque27 abr 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
anteriorpágina 154 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.