Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware28 mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-21643CRITICALbajo ataque28 mar 2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL28 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL28 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
VulnCheck XDB
local
CVE-2026-23744CRITICAL28 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC7
CVE-2022-46364-Poc Apache CXF SSRF via MTOM XOP:Include
CVE-2022-46364CRITICAL28 mar 2026
Apache CXF SSRF Vulnerability
48RIESGO
abrir
GitHub PoC
Explota vulnerabilidad
CVE-2023-43208CRITICALbajo ataqueransomware28 mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-33045CRITICALbajo ataque28 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
BOLA/IDOR vulnerability in osTicket ajax.tickets.php | Responsible Disclosure
CVE-2026-14871HIGH28 mar 2026
osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL28 mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RIESGO
abrir
GitHub PoC
CVE-2026-25099 — Bludit CMS API Unrestricted File Upload to Remote Code Execution
CVE-2026-25099HIGH28 mar 2026
Remote Code Execution via Unrestricted File Upload in Bludit
41RIESGO
abrir
GitHub PoC4
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
CVE-2021-33044CRITICALbajo ataque28 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
SentinelStream AI: A professional SIEM and SOAR platform featuring real-time threat correlation for CVE-2024-21410 and automated incident response logic.
CVE-2024-21410CRITICALbajo ataque27 mar 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL27 mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC6
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICAL27 mar 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-26229HIGH27 mar 2026
Windows CSC Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
BastianXploited/CVE-2025-6440
CVE-2025-6440CRITICAL27 mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC3
CVE-2026-33017: Unauthenticated RCE in Langflow
CVE-2026-33017CRITICALbajo ataque27 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
CVE-2018-13374MEDIUMbajo ataqueransomware27 mar 2026
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-15030CRITICAL27 mar 2026
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
48RIESGO
abrir
GitHub PoC
Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque27 mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Drupal 7 CMS vulnerable to CVE-2018-7600 (Drupalgeddon2), allowing unauthenticated remote code execution.
CVE-2018-7600CRITICALbajo ataqueransomware27 mar 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
python script for exploiting CVE-2026-23744
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC1
Exploit script for CVE-2026-23744
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-21643CRITICALbajo ataque27 mar 2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RIESGO
abrir
GitHub PoC
Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)
CVE-2025-31277HIGHbajo ataque27 mar 2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, mac
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
anteriorpágina 170 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.