Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9029Nuclei 4416Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
GitHub PoC★ 1
Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
Master's Thesis research on CVE-2024-30051 (Windows DWM Heap Overflow). Features a high-reliability exploit with automated heap spray optimization, real-time logging, and empirical success-rate analysis. Portfolio piece demonstrating advanced Windows binary exploitation, heap layout manipulation, and LPE via Desktop Window Manager.
Windows DWM Core Library Elevation of Privilege Vulnerability
71RIESGO
abrir ↗VulnCheck XDB
initial-access
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
63RIESGO
abrir ↗VulnCheck XDB
local
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
28RIESGO
abrir ↗GitHub PoC★ 1
Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret Exfiltration), an interactive reverse shell, and a complete laboratory. Portfolio piece demonstrating deep analysis of Prototype Pollution and Insecure Deserialization in React Server Components
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
PoC for CVE-2025-49596 on linux targets
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RIESGO
abrir ↗GitHub PoC★ 5
WinRAR < 7.13 path traversal for persistency
Path traversal vulnerability in WinRAR
93RIESGO
abrir ↗GitHub PoC
NeoArtemis37/OverlayFS-PrivEsc-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RIESGO
abrir ↗GitHub PoC
CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0
41RIESGO
abrir ↗GitHub PoC★ 1
Camera Dahua Research lỗ hổng CVE-2021-33044
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗GitHub PoC
RandyNin/CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC
CVE-2025-55182 — React2Shell
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC★ 1
Exploit to MCPJam Inspector <=1.4.2
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir ↗GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
local
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RIESGO
abrir ↗GitHub PoC
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.
Windows OLE Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
13RIESGO
abrir ↗GitHub PoC
Investigating CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
info-leak
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗GitHub PoC
Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗GitHub PoC
CVE-2018-7422
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir ↗GitHub PoC★ 1
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.