Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 feb 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RIESGO
abrir
GitHub PoC136
huseyinstif/CVE-2026-2441-PoC
CVE-2026-2441HIGHbajo ataque18 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
GitHub PoC1
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALbajo ataque18 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALbajo ataqueransomware18 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALbajo ataqueransomware18 feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque18 feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-
CVE-2026-24061CRITICALbajo ataque18 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC2
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
CVE-2020-0688HIGHbajo ataqueransomware18 feb 2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALbajo ataque17 feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
Interactive shell client for React Server Components RCE exploitation via __proto__ pollution (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware17 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque17 feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC
New CVE-2019-7609 which works with python 13
CVE-2019-7609CRITICALbajo ataque17 feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALbajo ataqueransomware17 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
PoC and explanation for CVE-2025-4517 used in a CTF I was playing.
CVE-2025-4517CRITICAL17 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALbajo ataque17 feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque17 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC2
CVE-2025-47812 POC
CVE-2025-47812CRITICALbajo ataque17 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque17 feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
rogerzeferino/Apache-Solr-RCE-CVE-2019-17558
CVE-2019-17558HIGHbajo ataque16 feb 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC1
rogerzeferino/cve-2019-17558-apache-solr-rce
CVE-2019-17558HIGHbajo ataque16 feb 2026
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49132CRITICAL16 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-23744-Lab
CVE-2026-23744CRITICAL16 feb 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
A high-performance Python toolkit to automate the CVE-2025-4517 PATH_MAX bypass exploit. Specifically tuned for the WingData HTB challenge to achieve arbitrary file writes and root persistence
CVE-2025-4517CRITICAL16 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC4
CVE For Pterodactyl (For Study and Education)
CVE-2025-49132CRITICAL16 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
Authenticated RCE in Netgate pfSense CE 2.7.2 and 2.8.0
CVE-2025-69690CRITICAL16 feb 2026
Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL16 feb 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC8
Privilege Escalation script for CVE-2025-4517
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque15 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
anteriorpágina 192 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.