Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34414HIGH22 abr 2026
Xerte Online Toolkits Path Traversal via connector.php
56RIESGO
abrir
GitHub PoC
Sanitized advisory for CVE-2025-51846 affecting CryptPad WebSocket handling.
CVE-2025-51846HIGH22 abr 2026
CryptPad unbounded WebSocket frame flood
41RIESGO
abrir
GitHub PoC
CVEs-Labs/CVE-2026-21876
CVE-2026-21876CRITICAL22 abr 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RIESGO
abrir
GitHub PoC
Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.
CVE-2017-0144HIGHbajo ataqueransomware22 abr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC2
SQL Injection vulnerability in NASA EOSDIS MODAPS due to improper input validation in the `category` parameter. This flaw allows attackers to manipulate backend SQL queries, potentially leading to unauthorized data access and database compromise.
CVE-2024-46636CRITICAL22 abr 2026
NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v
48RIESGO
abrir
GitHub PoC
jpselva/CVE-2023-4863
CVE-2023-4863HIGHbajo ataque22 abr 2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware22 abr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34413HIGH22 abr 2026
Xerte Online Toolkits Missing Authentication via connector.php
56RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque22 abr 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC4
Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110
CVE-2025-58434CRITICAL22 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2022-1026HIGH22 abr 2026
Kyocera Net View Address Book Exposure
61RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2022-3590MEDIUM22 abr 2026
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
48RIESGO
abrir
Exploit-DB
WordPress Plugin 5.2.0 - Broken Access Control
CVE-2025-67586MEDIUMwebappsmultiple22 abr 2026
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RIESGO
abrir
GitHub PoC
CVE-2019-15107 Webmin RCE (unauthenticated) exploit
CVE-2019-15107CRITICALbajo ataqueransomware22 abr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware22 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
Flowise CSV Agent Prompt Injection RCE
CVE-2026-41264CRITICAL22 abr 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
43RIESGO
abrir
GitHub PoC1
(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)
CVE-2026-29053HIGH21 abr 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RIESGO
abrir
GitHub PoC
ClaraSto/CVE-2024-1086_Ausarbeitung
CVE-2024-1086HIGHbajo ataqueransomware21 abr 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC
Black-box test whether an LLM chatbot is vulnerable to markdown/HTML exfil (CVE-2025-32711 class). Spins up a sink, sends payloads, renders in headless Chromium, correlates via network.
CVE-2025-32711CRITICAL20 abr 2026
M365 Copilot Information Disclosure Vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALbajo ataqueransomware20 abr 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC79
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
CVE-2026-34197HIGHbajo ataque20 abr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
GitHub PoC83
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
CVE-2016-3088CRITICALbajo ataque20 abr 2026
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque20 abr 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC1
Jorrit-VM/CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque20 abr 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC1
The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO).
CVE-2025-58434CRITICAL20 abr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RIESGO
abrir
GitHub PoC
Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.
CVE-2017-0144HIGHbajo ataqueransomware20 abr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner
CVE-2026-42208CRITICALbajo ataque20 abr 2026
LiteLLM: SQL injection in Proxy API key verification
100RIESGO
abrir
GitHub PoC
Type Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab
CVE-2021-3493HIGHbajo ataque20 abr 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC77
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
CVE-2023-46604CRITICALbajo ataqueransomware20 abr 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVE-2026-3462MEDIUM20 abr 2026
Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
33RIESGO
abrir
anteriorpágina 157 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.