Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
GitHub PoC1
Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online
CVE-2022-30190HIGHbajo ataqueransomware25 mar 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing
CVE-2025-55182CRITICALbajo ataqueransomware25 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Master's Thesis research on CVE-2024-30051 (Windows DWM Heap Overflow). Features a high-reliability exploit with automated heap spray optimization, real-time logging, and empirical success-rate analysis. Portfolio piece demonstrating advanced Windows binary exploitation, heap layout manipulation, and LPE via Desktop Window Manager.
CVE-2024-30051HIGHbajo ataqueransomware25 mar 2026
Windows DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-3584CRITICAL25 mar 2026
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL25 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
local
CVE-2024-51324LOW25 mar 2026
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL25 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC1
Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret Exfiltration), an interactive reverse shell, and a complete laboratory. Portfolio piece demonstrating deep analysis of Prototype Pollution and Insecure Deserialization in React Server Components
CVE-2025-55182CRITICALbajo ataqueransomware25 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
PoC for CVE-2025-49596 on linux targets
CVE-2025-49596CRITICAL25 mar 2026
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RIESGO
abrir
GitHub PoC5
WinRAR < 7.13 path traversal for persistency
CVE-2025-8088HIGHbajo ataqueransomware25 mar 2026
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
NeoArtemis37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL25 mar 2026
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir
GitHub PoC
CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2
CVE-2026-31278HIGH25 mar 2026
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0
41RIESGO
abrir
GitHub PoC1
Camera Dahua Research lỗ hổng CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque24 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
RandyNin/CVE-2023-4220
CVE-2023-4220HIGH24 mar 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
CVE-2025-55182 — React2Shell
CVE-2025-55182CRITICALbajo ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Exploit to MCPJam Inspector <=1.4.2
CVE-2026-23744CRITICAL24 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH24 mar 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32784HIGH24 mar 2026
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir
GitHub PoC
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.
CVE-2025-21298CRITICAL24 mar 2026
Windows OLE Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider
CVE-2026-32794MEDIUM24 mar 2026
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
13RIESGO
abrir
GitHub PoC
Investigating CVE-2022-36804
CVE-2022-36804HIGHbajo ataque24 mar 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware24 mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL24 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-33044CRITICALbajo ataque24 mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.
CVE-2012-595823 mar 2026
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL23 mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-2473MEDIUM23 mar 2026
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
48RIESGO
abrir
GitHub PoC
CVE-2018-7422
CVE-2018-742223 mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC1
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.
CVE-2025-66398CRITICAL23 mar 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RIESGO
abrir
anteriorpágina 172 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.