Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.645exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
GitHub PoC
kaleth4/-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque09 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
kaleth4/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque09 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force authentication attempts and exploitation attempts targeting Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALbajo ataqueransomware09 abr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Majdae/CVE-2025-47812-Research
CVE-2025-47812CRITICALbajo ataque09 abr 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Exploit-DB
React Server 19.2.0 - Remote Code Execution
CVE-2025-55182CRITICALbajo ataqueransomwarewebappsmultiple09 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-21858CRITICAL09 abr 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque09 abr 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676309 abr 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC2
CVE-2025-63353
CVE-2025-63353CRITICAL09 abr 2026
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RIESGO
abrir
Exploit-DB
SQLite 3.50.1 - Heap Overflow
CVE-2025-6965HIGHlocalwindows08 abr 2026
Integer Truncation on SQLite
63RIESGO
abrir
GitHub PoC
HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM pam_environment bypass) + CVE-2025-6019 (udisks2 XFS resize race condition, nosuid bypass) → root. Full notes and steps included.
CVE-2025-49132CRITICAL08 abr 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
CVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis
CVE-2020-1938CRITICALbajo ataque08 abr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Security review уязвимости CVE-2024-3094 с открытым исходным кодом
CVE-2024-3094CRITICAL08 abr 2026
Xz: malicious code in distributed source
70RIESGO
abrir
Exploit-DB
Microsoft MMC MSC EvilTwin - Local Admin Creation
CVE-2025-26633HIGHbajo ataqueransomwarelocalwindows08 abr 2026
Microsoft Management Console Security Feature Bypass Vulnerability
83RIESGO
abrir
Exploit-DB
xibocms 3.3.4 - RCE
CVE-2023-33177HIGHwebappsmultiple08 abr 2026
Xibo CMS vulnerable to Remote Code Execution through Zip Slip
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-34197HIGHbajo ataque08 abr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-34197HIGHbajo ataque08 abr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
GitHub PoC3
POC
CVE-2026-0740CRITICAL08 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL08 abr 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
cyb3rk0ala/THM-MagnusBilling-CVE-2023-30258-Exploit
CVE-2023-30258CRITICAL08 abr 2026
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
Exploit-DB
Horilla v1.3 - RCE
CVE-2025-48868HIGHwebappsmultiple08 abr 2026
Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL08 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC
doaso/CVE-2023-42115
CVE-2023-42115CRITICAL08 abr 2026
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RIESGO
abrir
Exploit-DB
7-Zip 24.00 - Directory Traversal
CVE-2025-11001HIGHlocalmultiple08 abr 2026
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RIESGO
abrir
Exploit-DB
FortiWeb 8.0.2 - Remote Code Execution
CVE-2025-64446CRITICALbajo ataquewebappsmultiple08 abr 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC
e1st/CVE-2025-56015
CVE-2025-56015HIGH07 abr 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
41RIESGO
abrir
GitHub PoC
CVE-2025-13315
CVE-2025-13315CRITICAL07 abr 2026
Unauthenticated log access in Twonky Server
75RIESGO
abrir
GitHub PoC
Python Exploit for CVE: 2018-9276
CVE-2018-9276HIGHbajo ataque07 abr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
GitHub PoC
sathish46-lab/CVE-2025-48384-submodule
CVE-2025-48384HIGHbajo ataque07 abr 2026
Git allows arbitrary code execution through broken config quoting
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL07 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
anteriorpágina 164 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.