Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
GitHub PoC1
simple CVE-2017-7921 rewrite in python by me. for educational purposes only!
CVE-2017-7921CRITICALbajo ataque15 feb 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC2
CVE‑2025‑4517 Proof‑of‑Concept Script
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC2
CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
GitHub PoC8
Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330
CVE-2025-4517CRITICAL15 feb 2026
Arbitrary writes via tarfile realpath overflow
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque15 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7921CRITICALbajo ataque15 feb 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL15 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
CVE-2025-47812: Wing FTP Server 7.4.3 UnauthN RCE in sh
CVE-2025-47812CRITICALbajo ataque15 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
GitHub PoC
[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque15 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
CVE-2024-37383 Proof of Concept
CVE-2024-37383MEDIUMbajo ataque14 feb 2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL14 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE
CVE-2026-26335CRITICAL14 feb 2026
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
48RIESGO
abrir
GitHub PoC
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.
CVE-2026-24061CRITICALbajo ataque14 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
nik123-py/CVE-2025-49132_HTB_SEASON10
CVE-2025-49132CRITICAL14 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
Samba 3.0.20 CVE-2007-2447 Exploit
CVE-2007-244714 feb 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALbajo ataque14 feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-8088HIGHbajo ataqueransomware14 feb 2026
Path traversal vulnerability in WinRAR
93RIESGO
abrir
VulnCheck XDB
local
CVE-2025-70795MEDIUM14 feb 2026
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
33RIESGO
abrir
GitHub PoC5
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
CVE-2025-70830CRITICAL14 feb 2026
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
48RIESGO
abrir
GitHub PoC48
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
CVE-2026-0828HIGH14 feb 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RIESGO
abrir
GitHub PoC
Privilege escalation exploit chain (CVE-2025-6018 + CVE-2025-6019) for openSUSE Leap 15.6
CVE-2025-6018HIGH14 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 feb 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RIESGO
abrir
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 feb 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-37383MEDIUMbajo ataque14 feb 2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RIESGO
abrir
VulnCheck XDB
local
CVE-2023-42824HIGHbajo ataque14 feb 2026
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may
71RIESGO
abrir
VulnCheck XDB
local
CVE-2026-1357CRITICAL14 feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH14 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
GitHub PoC
Домашняя работа по Pyton № 10 CVE-2020-11022 Краткое описание CVE-2020-11022 — уязвимость типа Reflected XSS (межсайтовый скриптинг), связанная с некорректной обработкой пользовательского ввода, который отражается в HTML-ответе без экранирования. Атакующий может внедрить JavaScript-код, который выполнится в браузере пользователя.
CVE-2020-11022MEDIUM14 feb 2026
jQuery has a potential XSS vulnerability
55RIESGO
abrir
GitHub PoC49
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
CVE-2025-70795MEDIUM14 feb 2026
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT
33RIESGO
abrir
GitHub PoC2
Herramienta avanzada de explotación transversal de ruta de WinRAR para CVE-2025-8088
CVE-2025-8088HIGHbajo ataqueransomware14 feb 2026
Path traversal vulnerability in WinRAR
93RIESGO
abrir
anteriorpágina 193 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.