Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.666exploits catalogados
32.032CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.896GitHub PoC 13.204VulnCheck XDB 8127Nuclei 4191Metasploit 3462✓ solo verificadosrecientespopularesriesgo
71.666 exploits
GitHub PoC
Technical analysis of the LangChain serialization injection vulnerability CVE-2025-68664.
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
53RIESGO
abrir ↗GitHub PoC
A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path. Page-cache write into any readable file. Overwrites a nologin line in /etc/passwd with sick::0:0:…:/:/bin/bash and sus into it. Same class as Copy Fail (CVE-2026-31431), different subsystem.
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
ryan2929/CVE-2026-43284-
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗VulnCheck XDB
initial-access
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗GitHub PoC
Educational Proof of Concept for CVE-2026-31431 / Copy Fail Linux local privilege escalation via AF_ALG algif_aead
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 27
arm64/aarch64 port of V4bel/dirtyfrag (CVE-2026-43284). ESP-only - rxrpc path kernel-oopses on arm64 due to flush_dcache_page
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗VulnCheck XDB
initial-access
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RIESGO
abrir ↗VulnCheck XDB
info-leak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗GitHub PoC
kaleth4/CVE-2026-7482
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
21RIESGO
abrir ↗GitHub PoC
CVE-2026-7270 FreeBSD local privilege escalation via exec_args_adjust_args OOB memmove
Local privilege escalation via execve()
21RIESGO
abrir ↗GitHub PoC
Elegant C++ exploit for CVE-2026-31431 (Copy Fail) using AF_ALG authenticated encryption + splice(2) to overwrite setuid binary memory
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC★ 7
Read-only checker for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) Linux kernel local-root vulns
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗GitHub PoC★ 3
Read-only checker for CVE-2026-31431 (algif_aead local root). Reports kernel/module state and suggests mitigations.
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
A bash script for mitigating linux dirtyfrag exploit CVE-2026-43500, and fragnesia
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RIESGO
abrir ↗GitHub PoC
kaleth4/CVE-2026-32746
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir ↗GitHub PoC
Proof-of-concept exploits for CVE-2026-4390, CVE-2026-4391 and CVE-2026-4392 in TeamSpeak 3 server (3.13.7).
TeamSpeak 3 Server Connection State Management process_resend_queue use after free
33RIESGO
abrir ↗GitHub PoC
Kernel patches for Dirty Frag vulnerability (CVE-2026-43284, CVE-2026-43500)
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗GitHub PoC
Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
CVE-2020-1938 Exploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir ↗GitHub PoC
Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware simulation, VAPT analysis, and security patch implementation in a controlled lab environment.
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗GitHub PoC
Black-box penetration test on Metasploitable 2 — Identified 3 critical vulnerabilities including CVE-2011-2523. Conducted in isolated VMware lab. Tools: Nmap, Metasploit, Netcat.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC★ 2
CVE-2020-14008 - ManageEngine Applications Manager RCE
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-21510 LNK generator PoC
Windows Shell Security Feature Bypass Vulnerability
76RIESGO
abrir ↗GitHub PoC
Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC
Helios973/CVE-2026-31431_exp.c
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.