Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.805 exploits
Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
CVE-2026-27174CRITICAL18 feb 2026
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RIESGO
abrir
Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
CVE-2026-2329CRITICAL18 feb 2026
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALbajo ataqueransomware18 feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque18 feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-919418 feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALbajo ataque17 feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque17 feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALbajo ataqueransomware17 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware17 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
CVE-2025-4517CRITICAL17 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
New CVE-2019-7609 which works with python 13
CVE-2019-7609CRITICALbajo ataque17 feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALbajo ataque17 feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque17 feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque17 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC2
CVE-2025-47812 POC
CVE-2025-47812CRITICALbajo ataque17 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49132CRITICAL16 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL16 feb 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
rogerzeferino/Apache-Solr-RCE-CVE-2019-17558
CVE-2019-17558HIGHbajo ataque16 feb 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC1
rogerzeferino/cve-2019-17558-apache-solr-rce
CVE-2019-17558HIGHbajo ataque16 feb 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC4
CVE For Pterodactyl (For Study and Education)
CVE-2025-49132CRITICAL16 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0
CVE-2025-69690CRITICAL16 feb 2026
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
48RIESGO
abrir
GitHub PoC
A high-performance Python toolkit to automate the CVE-2025-4517 PATH_MAX bypass exploit. Specifically tuned for the WingData HTB challenge to achieve arbitrary file writes and root persistence
CVE-2025-4517CRITICAL16 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-23744-Lab
CVE-2026-23744CRITICAL16 feb 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC2
CVE‑2025‑4517 Proof‑of‑Concept Script
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7921CRITICALbajo ataque15 feb 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC8
Privilege Escalation script for CVE-2025-4517
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC8
Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC2
CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque15 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
anteriorpágina 191 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.