Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.646 exploits
VulnCheck XDB
initial-access
CVE-2026-21902CRITICAL28 feb 2026
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
53RIESGO
abrir
GitHub PoC
Metasploit exploit for the CVE-2025-50286.
CVE-2025-50286HIGH28 feb 2026
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-30190HIGHbajo ataqueransomware28 feb 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-35250HIGHbajo ataque27 feb 2026
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALbajo ataqueransomware27 feb 2026
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC
ArthurHendrich/CVE-2022-42475-POC
CVE-2022-42475CRITICALbajo ataqueransomware27 feb 2026
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21445CRITICALbajo ataque27 feb 2026
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RIESGO
abrir
GitHub PoC7
CVE-2024-35250 demonstrates that HVCI is not a defense against data-only kernel exploits. As long as a driver bug provides an arbitrary R/W primitive, token swap remains a universal SYSTEM elevation technique — no code execution required.
CVE-2024-35250HIGHbajo ataque27 feb 2026
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-1581HIGH27 feb 2026
wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection
56RIESGO
abrir
GitHub PoC5
Exploit for CVE-2022-21445 of Oracle Weblogic 12.2.1.X
CVE-2022-21445CRITICALbajo ataque27 feb 2026
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RIESGO
abrir
GitHub PoC
Confluence Unauth RCE (CVE-2022-26134)
CVE-2022-26134CRITICALbajo ataqueransomware26 feb 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC2
CVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operations, and pre-auth interactions. Designed for safe security research and analysis.
CVE-2025-32433CRITICALbajo ataque26 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-32433CRITICALbajo ataque26 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Security Advisory & PoC for CVE-2025-70994 (Yadea T5 CWE-1390). Details on EV1527 RF replay vulnerabilities, coordinated with CISA.
CVE-2025-70994HIGH26 feb 2026
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent
41RIESGO
abrir
GitHub PoC
CVE-2024-23692 | HFS 2.3m/2.4-RC07 RCE vulnerability fix
CVE-2024-23692CRITICALbajo ataqueransomware26 feb 2026
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-27174CRITICAL26 feb 2026
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-0160HIGHbajo ataque26 feb 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
Python implementation of CVE-2023-43208 Mirth Connect RCE (Unauth XStream)
CVE-2023-43208CRITICALbajo ataqueransomware26 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-891726 feb 2026
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-891726 feb 2026
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL26 feb 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware26 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
Lab with PoC
CVE-2025-55182CRITICALbajo ataqueransomware26 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware26 feb 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-36804HIGHbajo ataque26 feb 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
A lightweight orchestrator and worker scanner setup for running large/continuous scans across split input files. This repository contains orchestration scripts, a Docker-based worker image, and helper scripts to run scans repeatedly and collect results.
CVE-2025-55182CRITICALbajo ataqueransomware26 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware26 feb 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-40553CRITICAL26 feb 2026
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware26 feb 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-553126 feb 2026
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
anteriorpágina 185 / 2689siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.