Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
13.235 exploits
GitHub PoC
Simple and effective PoC for CVE-2021-43798 Grafana Path Traversal
CVE-2021-43798HIGHbajo ataque27 ene 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC6
This is a security exploit tool targeting CVE-2025-55182. It exploits a Remote Code Execution (RCE) vulnerability in React Server Components
CVE-2025-55182CRITICALbajo ataqueransomware27 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
0xLittleSpidy/CVE-2025-54309
CVE-2025-54309CRITICALbajo ataque27 ene 2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RIESGO
abrir
GitHub PoC
An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving near-perfect theoretical rating through quantum temporal resonance and α-dispersion techniques.
CVE-2021-26855CRITICALbajo ataqueransomware27 ene 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Sn0wBaall/CVE-2024-23334-PoC
CVE-2024-23334MEDIUM27 ene 2026
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RIESGO
abrir
GitHub PoC
Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known RCE with patches available, perfect for demonstrating CTT enhancements.
CVE-2021-21972CRITICALbajo ataqueransomware27 ene 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
CVE-2025-24893 | Vulnérabilité d'exécution de code à distance sur la plateforme XWiki (preuve de concept)
CVE-2025-24893CRITICALbajo ataque26 ene 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
CVE-2025-41243CRITICAL26 ene 2026
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RIESGO
abrir
GitHub PoC
afifudinmtop/CVE-2009-3103
CVE-2009-310326 ene 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
GitHub PoC
🔍 Analyze WebKit and ANGLE vulnerabilities with this repository for CVE-2025-43529 and CVE-2025-14174, focusing on verified components and ongoing efforts.
CVE-2025-43529HIGHbajo ataque26 ene 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
GitHub PoC1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
CVE-2025-29927CRITICAL26 ene 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALbajo ataque25 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque25 ene 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 ene 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 ene 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RIESGO
abrir
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 ene 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RIESGO
abrir
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMbajo ataque25 ene 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC
jagg3rsec/CVE-2014-6287
CVE-2014-6287CRITICALbajo ataque25 ene 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHbajo ataqueransomware25 ene 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 ene 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 ene 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHbajo ataque24 ene 2026
SSRF in adminer
100RIESGO
abrir
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware24 ene 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.
CVE-2025-52691CRITICALbajo ataqueransomware23 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC2
Sairbo/Unihackers---CVE-2025-55182-
CVE-2025-55182CRITICALbajo ataqueransomware23 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC2
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via the `kubio_hybrid_theme_load_template` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files..
CVE-2025-2294CRITICAL23 ene 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
GitHub PoC
Replica of CVE-2019-15715 in Python3
CVE-2019-1571523 ene 2026
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RIESGO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP webshell and achieve remote command execution without authentication, including OS detection and an interactive shell.
CVE-2023-51409CRITICAL22 ene 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RIESGO
abrir
GitHub PoC1
Exploit for CVE-2023-40028 (for educational purposes)
CVE-2023-40028MEDIUM22 ene 2026
Arbitrary file read via symlinks in Ghost
45RIESGO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute arbitrary PHP code, write a web shell to the uploads directory, detect the target operating system, and achieve remote command execution via an interactive shell.
CVE-2024-50498CRITICAL22 ene 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.