Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.805 exploits
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataqueransomware20 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Path traversal vulnerability in Python's tarfile.
CVE-2025-4517CRITICAL20 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware20 feb 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
CVE-2025-71243CRITICAL19 feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RIESGO
abrir
GitHub PoC
CVE-2022-24521 poc
CVE-2022-24521HIGHbajo ataqueransomware19 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
CVE-2014-6271CRITICALbajo ataque19 feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
这是基于cve-2016-4437简单的漏洞复现代码
CVE-2016-4437CRITICALbajo ataque19 feb 2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2026-2441HIGHbajo ataque19 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-71243CRITICAL19 feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RIESGO
abrir
VulnCheck XDB
local
CVE-2022-24521HIGHbajo ataqueransomware19 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC2
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
CVE-2025-47812CRITICALbajo ataque19 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque19 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALbajo ataque19 feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
GitHub PoC
theemperorspath/CVE-2026-2441-PoC
CVE-2026-2441HIGHbajo ataque19 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque19 feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALbajo ataque19 feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALbajo ataqueransomware18 feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque18 feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Lab Environment for CVE-2026-22241
CVE-2026-22241HIGH18 feb 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RIESGO
abrir
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALbajo ataqueransomware18 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-47812CRITICALbajo ataque18 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
CVE-2025-4517CRITICAL18 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-
CVE-2026-24061CRITICALbajo ataque18 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALbajo ataque18 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque18 feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-919418 feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 feb 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RIESGO
abrir
anteriorpágina 190 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.