Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.803exploits catalogados
37.492CVEs con explotación pública
24.695probados en laboratorio
80.803 exploits
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware23 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHbajo ataque23 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2024-53704HIGHbajo ataqueransomware23 feb 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2021-20038CRITICALbajo ataqueransomware23 feb 2026
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH22 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
GitHub PoC1
Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.
CVE-2021-36934HIGHbajo ataque22 feb 2026
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32463CRITICALbajo ataque22 feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)
CVE-2024-46987HIGH22 feb 2026
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir
GitHub PoC
RCE for WingFTP v4.7.3
CVE-2025-47812CRITICALbajo ataque22 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
danilo1992-sys/CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque22 feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
iOxsec/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit
CVE-2025-6018HIGH22 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
GitHub PoC1
PoC for Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC3
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
GitHub PoC
Stored Cross-Site Scripting in "usememos" via SVG
CVE-2025-50738CRITICAL22 feb 2026
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque22 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALbajo ataqueransomware22 feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHbajo ataque21 feb 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-68645HIGHbajo ataque21 feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir
GitHub PoC
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.
CVE-2025-49132CRITICAL21 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC1
Exploitation de CVE-2022-26923
CVE-2022-26923HIGHbajo ataque21 feb 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL21 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
its970/CVE-2025-68645
CVE-2025-68645HIGHbajo ataque21 feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir
GitHub PoC
CVE-2022-37969 poc
CVE-2022-37969HIGHbajo ataqueransomware20 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataqueransomware20 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.
CVE-2017-5638CRITICALbajo ataqueransomware20 feb 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware20 feb 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC
Path traversal vulnerability in Python's tarfile.
CVE-2025-4517CRITICAL20 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
C reimplementation of chwoot PoC
CVE-2025-32463CRITICALbajo ataque20 feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-1405CRITICAL20 feb 2026
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
anteriorpágina 189 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.