Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
VulnCheck XDB
initial-access
CVE-2024-11680CRITICALbajo ataque31 mar 2026
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
Hoverfly CVE RCE
CVE-2025-54123CRITICAL31 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
wtbacon/cve-2018-15473
CVE-2018-15473MEDIUM31 mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
Setup and exploit recreation for CVE-2022-42889 Text4Shell.
CVE-2022-4288930 mar 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL30 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
PoC CVE-2025-54123 - Hoverfly <= 1.11.3 - Authenticated Middleware Command Injection
CVE-2025-54123CRITICAL30 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC1
akelaqe/CVE-2024-27348-HugeGraph-RCE
CVE-2024-27348CRITICALbajo ataque30 mar 2026
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
vettrivel007/CVE-2024-1086
CVE-2024-1086HIGHbajo ataqueransomware30 mar 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC
CVE-2022-22947 vulnerability task
CVE-2022-22947CRITICALbajo ataque30 mar 2026
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALbajo ataque30 mar 2026
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
amikanev/CVE-2025-55182-LAB
CVE-2025-55182CRITICALbajo ataqueransomware30 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
JacobTaylor3/CVE-2021-21220
CVE-2021-21220HIGHbajo ataque30 mar 2026
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-1086HIGHbajo ataqueransomware30 mar 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC
CVE-2024-6387 OpenSSH 信号竞争漏洞(regreSSHion)分析报告及检测脚本
CVE-2024-6387HIGH30 mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon kuralları ve IOC listesi.
CVE-2023-46604CRITICALbajo ataqueransomware30 mar 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Metasploit600
Supsystic Contact Form Wordpress Plugin SSTI RCE
CVE-2026-4257CRITICAL30 mar 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RIESGO
abrir
GitHub PoC2
This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests. The issue exists in how the href attribute of xop:Include is parsed, allowing arbitrary URLs to be requested by the server.
CVE-2022-46364CRITICAL29 mar 2026
Apache CXF SSRF Vulnerability
48RIESGO
abrir
GitHub PoC1
Shashivanth009/CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC
CVE-2022-46364CRITICAL29 mar 2026
Apache CXF SSRF Vulnerability
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL29 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
CVE-2025-54123 exploit and documentation
CVE-2025-54123CRITICAL29 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC10
💣 Exploit for CVE-2026-26980 — 👻 Ghost CMS Unauthenticated SQLi via Content API
CVE-2026-26980CRITICAL29 mar 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-26980CRITICAL29 mar 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
GitHub PoC
0x0asif/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware29 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection
CVE-2026-23744CRITICAL29 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL29 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware29 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
BOLA/IDOR vulnerability in osTicket ajax.tickets.php | Responsible Disclosure
CVE-2026-14871HIGH28 mar 2026
osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
41RIESGO
abrir
GitHub PoC4
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
CVE-2021-33044CRITICALbajo ataque28 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-33045CRITICALbajo ataque28 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
anteriorpágina 169 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.