Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALbajo ataque13 feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH13 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-1357CRITICAL13 feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC1
Vulnerability chaining leads to privilege escalation
CVE-2025-6018HIGH13 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH13 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
GitHub PoC4
watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553
CVE-2025-40552CRITICAL13 feb 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RIESGO
abrir
GitHub PoC1
CVE-2024-34102 exploit for python3
CVE-2024-34102CRITICALbajo ataque13 feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RIESGO
abrir
GitHub PoC1
针对 Next.js 原型污染漏洞 (CVE-2025-55182) 的高效批量检测工具。
CVE-2025-55182CRITICALbajo ataqueransomware13 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
CVE-2025-55182CRITICALbajo ataqueransomware13 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware13 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware12 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
CVE-2025-61882CRITICALbajo ataqueransomware12 feb 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC1
Exploit CVE-2025-49132 Pterodactyl Panel RCE
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
scroollocker/CVE-2025-49132
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC
mbanyamer/CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown
CVE-2026-26235HIGH12 feb 2026
JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication
41RIESGO
abrir
GitHub PoC
Sn0wBaall/CVE-2023-4220-PoC
CVE-2023-4220HIGH12 feb 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC5
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition LPE to root
CVE-2025-6018HIGH12 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
GitHub PoC3
CVE-2025-49132_PHP_PEAR_METHOD
CVE-2025-49132CRITICAL12 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
GitHub PoC2
React2Shell (CVE-2025-55182) POC
CVE-2025-55182CRITICALbajo ataqueransomware12 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH12 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH12 feb 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL11 feb 2026
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RIESGO
abrir
VulnCheck XDB
local
CVE-2025-6019HIGH11 feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RIESGO
abrir
GitHub PoC
ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
CVE-2021-41773HIGHbajo ataqueransomware11 feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
CVE-2025-6018 (pam LPE unpriv->allow_active), CVE-2025-6019 (udisks LPE allow_active->root) in sh
CVE-2025-6018HIGH11 feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir
GitHub PoC
Ahmedf000/CVE-2025-49132_HTB_SEASON10
CVE-2025-49132CRITICAL11 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL11 feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
anteriorpágina 194 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.