Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
VulnCheck XDB
initial-access
CVE-2025-15030CRITICAL18 abr 2026
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2026-25253HIGH18 abr 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque18 abr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13342CRITICAL18 abr 2026
Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-8110HIGHbajo ataque17 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM17 abr 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
GitHub PoC23
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload
CVE-2026-0740CRITICAL17 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC
yutasato88/CVE-2021-3560-PolkitPrivilegeEsclation
CVE-2021-3560HIGHbajo ataque17 abr 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Published Details for this CVE
CVE-2025-66954MEDIUM17 abr 2026
A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to
33RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque17 abr 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
CVE-2021-25337
CVE-2021-25337MEDIUMbajo ataque17 abr 2026
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL17 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-26980CRITICAL17 abr 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
GitHub PoC
CVE-2025-8110 Specifically for the Silentium box on HTB.
CVE-2025-8110HIGHbajo ataque17 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL17 abr 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
GitHub PoC
Exploiting BlueKeep (CVE-2019-0708) on Windows 7 using Metasploit
CVE-2019-0708CRITICALbajo ataqueransomware17 abr 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Exploiting bluekeep (CVE-2019-0708) on windows 7 using metasplotable
CVE-2019-0708CRITICALbajo ataqueransomware17 abr 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Exploiting bluekeep (CVE-2019-0708)on windows 7 using metasploit (Educational lab)
CVE-2019-0708CRITICALbajo ataqueransomware17 abr 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Escaner de identificacion de vulnerabilidades para CVE-2025-4322
CVE-2025-4322CRITICAL17 abr 2026
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir
GitHub PoC19
CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)
CVE-2026-26980CRITICAL17 abr 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33032CRITICAL17 abr 2026
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RIESGO
abrir
GitHub PoC
coolkiee/CVE-2019-9053
CVE-2019-905317 abr 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
Samba CVE-2007-2447 Exploit
CVE-2007-244717 abr 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC13
Escalating privilege in the system from unsigned driver using throttlestop vulnerability
CVE-2025-7771HIGH17 abr 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49113CRITICALbajo ataque16 abr 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL16 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC1
CVE-2010-2075 exploit
CVE-2010-207516 abr 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC1
Investigation of a PAN-OS CVE-2024-3400 command injection attempt, analyzing payload delivery, internal processing, and execution validation based on log evidence.
CVE-2024-3400CRITICALbajo ataqueransomware16 abr 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
CVE-2025-24893 – XWiki SSTI unauthenticated RCE exploit (HackTheBox CTF)
CVE-2025-24893CRITICALbajo ataque16 abr 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHbajo ataqueransomware16 abr 2026
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
anteriorpágina 159 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.