Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware05 abr 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
vettrivel007/CVE-2024-49138
CVE-2024-49138HIGHbajo ataque04 abr 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Analysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)
CVE-2025-29927CRITICAL04 abr 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
Pre-authentication LFI Lead to RCE
CVE-2026-39938CRITICAL04 abr 2026
Cacti: Unauthenticated RCE on Graph Image
48RIESGO
abrir
GitHub PoC
ElinaNotElina/cve-2024-3094-analysis
CVE-2024-3094CRITICAL04 abr 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
Dahalsamir/CVE-2011-2523-exploit
CVE-2011-252304 abr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
VulnCheck XDB
local
CVE-2024-49138HIGHbajo ataque04 abr 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Technical analysis of CVE-2025-55182 (React2Shell RCE vulnerability)
CVE-2025-55182CRITICALbajo ataqueransomware04 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)
CVE-2026-5027HIGH03 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC1
CVE-2026-0770
CVE-2026-0770CRITICALbajo ataque03 abr 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-5027HIGH03 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-3007503 abr 2026
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-5027HIGH03 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC1
TP-Link Router Authenticated RCE Exploit (CVE-2022-30075) Bu araç, TP-Link Archer AX50 ve bazı diğer TP-Link router modellerinde bulunan **CVE-2022-30075** güvenlik açığını kullanarak kimliği doğrulanmış uzaktan komut çalıştırma (Authenticated Remote Code Execution) işlemi gerçekleştirir.
CVE-2022-3007503 abr 2026
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RIESGO
abrir
GitHub PoC
tryj/CVE-2012-1823---PHP-CGI---RCE
CVE-2012-1823CRITICALbajo ataque03 abr 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC2
Perforce security research and tools - CVE-2026-6043
CVE-2026-6043HIGH03 abr 2026
Insecure Default Configuration in P4 Server
41RIESGO
abrir
GitHub PoC
Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075
CVE-2026-53075HIGH03 abr 2026
ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
41RIESGO
abrir
GitHub PoC1
Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.
CVE-2025-55182CRITICALbajo ataqueransomware03 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-5027
CVE-2026-5027HIGH03 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC3
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal
CVE-2026-5027HIGH03 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC1
Exploit CVE-2022-46363
CVE-2022-46364CRITICAL03 abr 2026
Apache CXF SSRF Vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2025-59059: Misattributed RCE in Apache Ranger Static Analysis Correction
CVE-2025-59059CRITICAL03 abr 2026
Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator
48RIESGO
abrir
GitHub PoC
CVE-2026-34156
CVE-2026-34156CRITICAL03 abr 2026
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
75RIESGO
abrir
GitHub PoC
CVE-2025-29927 - Next.js漏洞测试工具
CVE-2025-29927CRITICAL02 abr 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware02 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Second CVE still Remote Code Execution
CVE-2026-35196HIGH02 abr 2026
Chamilo LMS has OS Command Injection via export_all_certificates action
41RIESGO
abrir
GitHub PoC
This repository contains a comprehensive security assessment of an enterprise LAN environment. The core focus of this project was the identification, exploitation, and remediation of the **Shellshock (CVE-2014-6271)** vulnerability within a Linux-based web server.
CVE-2014-6271CRITICALbajo ataque02 abr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
🛡️ SSH User Enumeration (CVE-2018-15473). Python 3, multihilo y calibración anti-falsos positivos. 🧵
CVE-2018-15473MEDIUM02 abr 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-5027HIGH02 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC8
POC for CVE-2026-23416 (linux kernel 6.17 – linux kernel 7 rc5) - vulnerability discovered by Antonius
CVE-2026-2341602 abr 2026
mm/mseal: update VMA end correctly on merge
23RIESGO
abrir
anteriorpágina 167 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.