Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-69985CRITICAL25 feb 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RIESGO
abrir
GitHub PoC1
PoC for CVE-2023-43208 RCE exploitation.
CVE-2023-43208CRITICALbajo ataqueransomware25 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
mirth-connect-rce-poc
CVE-2023-43208CRITICALbajo ataqueransomware25 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).
CVE-2023-4966CRITICALbajo ataqueransomware25 feb 2026
Unauthenticated sensitive information disclosure
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22555HIGHbajo ataque25 feb 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC
TeneBrae93/RocketChat-NoSQLi-Chain-CVE-2021-22911
CVE-2021-2291125 feb 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware25 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-24481HIGH25 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
46RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque25 feb 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
GitHub PoC190
RSC Detect CVE 2025 55182
CVE-2025-55182CRITICALbajo ataqueransomware25 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.
CVE-2022-0185HIGHbajo ataque25 feb 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-2291125 feb 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-30258CRITICAL25 feb 2026
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware25 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-1357CRITICAL25 feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware25 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript
CVE-2025-69985CRITICAL25 feb 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RIESGO
abrir
GitHub PoC8
CVE-2026-25643: Frigate ≤0.16.3 Blind RCE via go2rtc exec injection
CVE-2026-25643CRITICAL24 feb 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RIESGO
abrir
GitHub PoC1
Langflow Remote Code Execution (RCE) Proof-of-Concept
CVE-2026-0770CRITICALbajo ataque24 feb 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware24 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0770CRITICALbajo ataque24 feb 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware24 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC1
0xjuarez/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque24 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
NetVanguard-cmd/CVE-2026-2441
CVE-2026-2441HIGHbajo ataque24 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-47812CRITICALbajo ataque24 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL24 feb 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
local
CVE-2026-21858CRITICAL24 feb 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
GitHub PoC
carlosalbertotuma/CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque24 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC2
The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.
CVE-2025-38352HIGHbajo ataque24 feb 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RIESGO
abrir
GitHub PoC3
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.
CVE-2023-43208CRITICALbajo ataqueransomware24 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
anteriorpágina 187 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.