Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9029Nuclei 4416Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Second CVE still Remote Code Execution
Chamilo LMS has OS Command Injection via export_all_certificates action
41RIESGO
abrir ↗VulnCheck XDB
client-side
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RIESGO
abrir ↗GitHub PoC
Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir ↗GitHub PoC★ 4
CVE-2026-5027 - Langflow Path Traversal to Remote Code Execution (CVSS 8.8)
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir ↗GitHub PoC
📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️
Grafana path traversal
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗GitHub PoC
FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir ↗GitHub PoC
kavin71725/CVE-2025-12543-Fix-for-Wildfly
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
48RIESGO
abrir ↗GitHub PoC
Analisis de CVE relacionada con stack overflow
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir ↗GitHub PoC★ 1
Technical analysis of a SharePoint ToolShell (CVE-2025-53770) exploitation attempt involving RCE, webshell deployment, and MachineKey extraction.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
TLevente20/HTTP-2-RapidReset-CVE-2023-44487-Testlab
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗GitHub PoC
CVE-2021-21220 Exploitation infrastructure
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir ↗GitHub PoC
Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗GitHub PoC★ 3
Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RIESGO
abrir ↗VulnCheck XDB
client-side
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗VulnCheck XDB
client-side
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir ↗GitHub PoC★ 11
Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir ↗GitHub PoC
Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir ↗GitHub PoC
kaleth4/CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC★ 11
Langflow RCE
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI
Apache CXF SSRF Vulnerability
48RIESGO
abrir ↗GitHub PoC
Hoverfly CVE RCE
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.