Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.646 exploits
Metasploit600
Ghost CMS Remote Code Execution
CVE-2026-22594HIGH02 mar 2026
Ghost has Staff 2FA bypass
36RIESGO
abrir
Metasploit600
Ghost CMS Remote Code Execution
CVE-2026-29053HIGH02 mar 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RIESGO
abrir
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-27636HIGH01 mar 2026
FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache
36RIESGO
abrir
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-28289CRITICAL01 mar 2026
FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
55RIESGO
abrir
GitHub PoC
Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847
CVE-2022-0847HIGHbajo ataque01 mar 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM01 mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
48RIESGO
abrir
GitHub PoC
Time-Based Blind SQL Injection Exploit for the OpenSIPs Control Panel (or my first CVE!)
CVE-2026-36670HIGH01 mar 2026
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr
41RIESGO
abrir
GitHub PoC1
Laravel-RCE: CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque01 mar 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
CVE-2014-0160
CVE-2014-0160HIGHbajo ataque01 mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque01 mar 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHbajo ataque01 mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHbajo ataqueransomware01 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware01 mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
7rootsec/CVE-2022-21661-Technical-Analysis
CVE-2022-21661HIGH01 mar 2026
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC
This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in Fortinet FortiWeb Fabric Connector versions 7.0 through 7.6.x. Successful exploitation can lead to Remote Code Execution without any prior authentication.
CVE-2025-25257CRITICALbajo ataque01 mar 2026
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RIESGO
abrir
GitHub PoC
D3b0j33t/CVE-2026-2441-PoC
CVE-2026-2441HIGHbajo ataque01 mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-9805HIGHbajo ataque28 feb 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
GarethMSheldon/CVE-2025-60787-Detection-motionEye-RCE-via-Config-Injection
CVE-2025-60787HIGH28 feb 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir
VulnCheck XDB
local
CVE-2024-21626HIGH28 feb 2026
runc container breakout through process.cwd trickery and leaked fds
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware28 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21902CRITICAL28 feb 2026
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
53RIESGO
abrir
GitHub PoC
Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.
CVE-2011-252328 feb 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
CVE-2017-9805 S2-052 PoC
CVE-2017-9805HIGHbajo ataque28 feb 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28517CRITICAL28 feb 2026
openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
63RIESGO
abrir
GitHub PoC
Metasploit exploit for the CVE-2025-50286.
CVE-2025-50286HIGH28 feb 2026
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28516CRITICAL28 feb 2026
openDCIM <= 23.04 SQL Injection in Config::UpdateParameter
43RIESGO
abrir
GitHub PoC
updated script
CVE-2019-905328 feb 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC1
Authenticated remote code execution in Pluck CMS before 4.7.13.
CVE-2020-2960728 feb 2026
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28515CRITICAL28 feb 2026
openDCIM <= 23.04 Missing Authorization in install.php
63RIESGO
abrir
GitHub PoC3
Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.
CVE-2025-55182CRITICALbajo ataqueransomware28 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 184 / 2689siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.