Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
14.316 exploits
GitHub PoC★ 1
CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC★ 1
Mitigation scripts for CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC★ 1
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC
CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir ↗GitHub PoC
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC
Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir ↗GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RIESGO
abrir ↗GitHub PoC
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC★ 2
Account takeover full PoC for CVE-2026-27886 in Strapi CMS
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
48RIESGO
abrir ↗GitHub PoC★ 2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
Apache HTTP Server: mod_http2 denial of service
46RIESGO
abrir ↗GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RIESGO
abrir ↗GitHub PoC
m0nk3ygod/CVE-2026-34040-PoC
Moby: AuthZ plugin bypass with oversized request body
46RIESGO
abrir ↗GitHub PoC★ 2
FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC
Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC
Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC★ 1
Exploit CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir ↗GitHub PoC★ 7
CVE-2025-57819 -> rce
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC★ 1
horrister/moveit-transfer-cve-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗GitHub PoC
Redacted cPanel/WHM authentication bypass analysis and authorized checker
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 8
0xEhab/FreePBX-CVE-2025-57819-RCE
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC
CVE-2026-20245 - Cisco SD-WAN - Draft
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
76RIESGO
abrir ↗GitHub PoC
Controlled NGINX HTTP/2 frame injection lab for CVE-2026-42926 patch validation and defensive research
NGINX ngx_http_proxy_v2_module vulnerability
33RIESGO
abrir ↗GitHub PoC
Proof-of-concept exploit for CVE-2026-24849, an authenticated path-traversal / arbitrary file read in OpenEMR's Fax/SMS (EtherFax) module. Any authenticated user regardless of privilege level can read arbitrary files from the server filesystem as the web-server user (database credentials, patient documents/PHI, /etc/passwd, …
OpenEMR Arbitrary File Read Vulnerability
48RIESGO
abrir ↗GitHub PoC
CVE-2026-23744 Reverse shell
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC
CVE-2023-46604-RCE exploit with Linux reverse shell payload
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC
t1ckprivate/CVE-2022-0847-Dirty-Pipe
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗GitHub PoC★ 1
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.