Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC
finding by nvth
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RIESGO
abrir ↗GitHub PoC★ 1
Metabase CVE-2026-59827 Vulnerability Scanner
Metabase: Unsafe Deserialization of H2 Query Results
48RIESGO
abrir ↗GitHub PoC★ 1
0xdak/CVE-2026-56121_exploit
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RIESGO
abrir ↗GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-63766_exploit
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RIESGO
abrir ↗GitHub PoC★ 1
CVE-2021-41773 Apache
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗GitHub PoC★ 4
soralis0912/CVE-2026-43499-aristotle
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 325
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the
41RIESGO
abrir ↗GitHub PoC
Dynamo2k1/CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC
CVE-2026-64600 - Draft - Check todo
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir ↗GitHub PoC
ghostpels/CVE-2026-13001
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RIESGO
abrir ↗GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC
CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction
Argument Injection in PHP-CGI
100RIESGO
abrir ↗GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir ↗GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir ↗GitHub PoC
Legacy HPE iMC vuln
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir ↗GitHub PoC
CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
41RIESGO
abrir ↗GitHub PoC★ 328
Certighost POC
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability detected during a target network scan.
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir ↗GitHub PoC
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created or supported by Check Point and should be used at your own risk.
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.