Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware02 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware02 abr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Second CVE still Remote Code Execution
CVE-2026-35196HIGH02 abr 2026
Chamilo LMS has OS Command Injection via export_all_certificates action
41RIESGO
abrir
VulnCheck XDB
client-side
CVE-2026-5281HIGHbajo ataque02 abr 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RIESGO
abrir
GitHub PoC
Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).
CVE-2022-0847HIGHbajo ataque02 abr 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-5027HIGH02 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC4
CVE-2026-5027 - Langflow Path Traversal to Remote Code Execution (CVSS 8.8)
CVE-2026-5027HIGH02 abr 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC
📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️
CVE-2021-43798HIGHbajo ataque02 abr 2026
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware01 abr 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.
CVE-2022-40684CRITICALbajo ataqueransomware01 abr 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
kavin71725/CVE-2025-12543-Fix-for-Wildfly
CVE-2025-12543CRITICAL01 abr 2026
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
48RIESGO
abrir
GitHub PoC
Analisis de CVE relacionada con stack overflow
CVE-2025-5548MEDIUM01 abr 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir
GitHub PoC1
Technical analysis of a SharePoint ToolShell (CVE-2025-53770) exploitation attempt involving RCE, webshell deployment, and MachineKey extraction.
CVE-2025-53770CRITICALbajo ataqueransomware01 abr 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-24054MEDIUMbajo ataque01 abr 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
TLevente20/HTTP-2-RapidReset-CVE-2023-44487-Testlab
CVE-2023-44487HIGHbajo ataque01 abr 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
CVE-2021-21220 Exploitation infrastructure
CVE-2021-21220HIGHbajo ataque01 abr 2026
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir
GitHub PoC
Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.
CVE-2025-24054MEDIUMbajo ataque01 abr 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC3
Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).
CVE-2026-48710MEDIUMbajo ataque01 abr 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-21220HIGHbajo ataque01 abr 2026
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque01 abr 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-2783HIGHbajo ataque01 abr 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC11
Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).
CVE-2025-2783HIGHbajo ataque01 abr 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC
Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)
CVE-2021-4034HIGHbajo ataqueransomware01 abr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
kaleth4/CVE-2024-6387
CVE-2024-6387HIGH31 mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-11680CRITICALbajo ataque31 mar 2026
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque31 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC11
Langflow RCE
CVE-2026-33017CRITICALbajo ataque31 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC1
CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI
CVE-2022-46364CRITICAL31 mar 2026
Apache CXF SSRF Vulnerability
48RIESGO
abrir
GitHub PoC
Hoverfly CVE RCE
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
anteriorpágina 168 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.