Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.790exploits catalogados
37.482CVEs con explotación pública
24.695probados en laboratorio
80.792 exploits
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL24 feb 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
VulnCheck XDB
local
CVE-2026-21858CRITICAL24 feb 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware24 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC1
0xjuarez/CVE-2025-47812
CVE-2025-47812CRITICALbajo ataque24 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0770CRITICALbajo ataque24 feb 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-47812CRITICALbajo ataque24 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
carlosalbertotuma/CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque24 feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC2
The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.
CVE-2025-38352HIGHbajo ataque24 feb 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RIESGO
abrir
GitHub PoC8
CVE-2026-25643: Frigate ≤0.16.3 Blind RCE via go2rtc exec injection
CVE-2026-25643CRITICAL24 feb 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RIESGO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in SPIP before 4.2.1.
CVE-2023-27372CRITICAL24 feb 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir
GitHub PoC
NetVanguard-cmd/CVE-2026-2441
CVE-2026-2441HIGHbajo ataque24 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC
atiilla/CVE-2026-2441_PoC
CVE-2026-2441HIGHbajo ataque23 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware23 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
tempiltin/CVE-2025-10353-POC
CVE-2025-10353CRITICAL23 feb 2026
Missing Authorization vulnerability in Melis Platform
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53704HIGHbajo ataqueransomware23 feb 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-31161CRITICALbajo ataqueransomware23 feb 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
Wrote an exploit in Go for CVE-2025-31161 affecting crushFTP.
CVE-2025-31161CRITICALbajo ataqueransomware23 feb 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHbajo ataque23 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47539CRITICAL23 feb 2026
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
68RIESGO
abrir
GitHub PoC
CVE-2025-14847
CVE-2025-14847HIGHbajo ataque23 feb 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2021-20038CRITICALbajo ataqueransomware23 feb 2026
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware23 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2024-53704HIGHbajo ataqueransomware23 feb 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque22 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC3
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC1
PoC for Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
iOxsec/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit
CVE-2025-6018HIGH22 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
GitHub PoC
PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)
CVE-2024-46987HIGH22 feb 2026
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir
GitHub PoC
Stored Cross-Site Scripting in "usememos" via SVG
CVE-2025-50738CRITICAL22 feb 2026
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us
48RIESGO
abrir
GitHub PoC1
Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.
CVE-2021-36934HIGHbajo ataque22 feb 2026
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
anteriorpágina 188 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.