Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.927exploits catalogados
37.571CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
VulnCheck XDB
denial-of-service
CVE-2023-28205HIGHbajo ataque04 ene 2026
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 a
76RIESGO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware04 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1420604 ene 2026
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote a
38RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-14174HIGHbajo ataque04 ene 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RIESGO
abrir
GitHub PoC10
CVE-2025-68926 - RustFS Hardcoded gRPC Authentication Token Exploit
CVE-2025-68926CRITICAL04 ene 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALbajo ataque03 ene 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-38352HIGHbajo ataque03 ene 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RIESGO
abrir
GitHub PoC
nuclei tamplate to CVE-2025-6440
CVE-2025-6440CRITICAL03 ene 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC1
rahuulmiishra/react2shell-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware03 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware03 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
CVE-2025-55182 漏洞检测与利用工具(GUI版)
CVE-2025-55182CRITICALbajo ataqueransomware03 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
n8n RCE (CVE-2025-68613)
CVE-2025-68613CRITICALbajo ataque03 ene 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
hyunnna/NextChat_SSRF_CVE-2023-49785
CVE-2023-49785CRITICAL03 ene 2026
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
85RIESGO
abrir
GitHub PoC
Expression injection payloads for n8n CVE-2025-68613 RCE
CVE-2025-68613CRITICALbajo ataque03 ene 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL03 ene 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
CVE-2025-55182 - Tool React2Shell
CVE-2025-55182CRITICALbajo ataqueransomware02 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution (CVE-2012-1823).
CVE-2012-1823CRITICALbajo ataque02 ene 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
🔍 Scan for CVE-2025-55182 vulnerabilities with a hybrid tool that combines static and dynamic analysis for improved security assessments.
CVE-2025-55182CRITICALbajo ataqueransomware02 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
A HackIndex.io sandbox environment for the React2Shell vulnerability.
CVE-2025-55182CRITICALbajo ataqueransomware02 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
🛡️ Scan and assess vulnerabilities in Next.js/Waku with the CVE-2025-55182-Scanner, combining static and dynamic analysis for robust security.
CVE-2025-55182CRITICALbajo ataqueransomware02 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Projeto educacional desenvolvido em Python com foco na análise da vulnerabilidade CVE-2021-3156 (Baron Samedit), uma falha crítica no sudo que permitia elevação de privilégio local em sistemas Linux.
CVE-2021-3156HIGHbajo ataque02 ene 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288902 ene 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
local
CVE-2025-14174HIGHbajo ataque02 ene 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL02 ene 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes a vulnerable Docker container with multi-database seeding (PII, API keys) and a Python exploit to demonstrate data extraction. Ideal for security research and awareness. 1-day analysis.
CVE-2025-14847HIGHbajo ataque02 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC1
Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code Execution (RCE) via script interpolation to establish a reverse shell. This version is a structured optimization based on the original exploit found at Exploit-DB (ID: 52261).
CVE-2022-4288902 ene 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
A custom Python proof-of-concept showcasing root-cause analysis and exploitation of CVE 2019-9978 (Social Warfare plugin),focusing on practical RFI to RCE attack flow.
CVE-2019-9978MEDIUMbajo ataque01 ene 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
MongoBleed CVE-2025-14847 Vulnerability Checker
CVE-2025-14847HIGHbajo ataque01 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
CVE-2025-52691
CVE-2025-52691CRITICALbajo ataqueransomware01 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC1
CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)
CVE-2025-55182CRITICALbajo ataqueransomware01 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 212 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.