Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
13.235 exploits
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
CVE-2026-23744CRITICAL20 ene 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
SSP H3
CVE-2024-38063CRITICAL20 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab
CVE-2024-21413CRITICALbajo ataque19 ene 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH – your global ecosystem for cybersecurity, AI apps, services, and consulting.
CVE-2025-12420CRITICAL19 ene 2026
Unauthenticated Privilege Escalation in ServiceNow AI Platform
60RIESGO
abrir
GitHub PoC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
CVE-2019-2725HIGHbajo ataqueransomware19 ene 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC
Killian0713/Assignement_3-CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque19 ene 2026
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
CVE-2023-0214MEDIUM19 ene 2026
XSS in Skyhigh Security SWG
33RIESGO
abrir
GitHub PoC
This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a root user inside a container can achieve a Host Root Shell by overwriting the host runc binary using an OverlayFS mount and ld.so.preload manipulation.
CVE-2019-573619 ene 2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC2
Teodor1231241/DEMO-Proof-of-Concept-Temporal-Memory-Inconsistency-in-cldflt.sys-CVE-2025-62221
CVE-2025-62221HIGHbajo ataque18 ene 2026
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
CVE-2024-11635CRITICAL18 ene 2026
WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution
48RIESGO
abrir
GitHub PoC
Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive suite—featuring multi-vector rotations, HTTP/2 Rapid Reset (CVE-2023-44487) exploitation, and mTLS 1.3-encrypted C2 orchestration—with a high-integrity 7-Tier Blue Elite Teaming defense-in-depth architecture.
CVE-2023-44487HIGHbajo ataque18 ene 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
rdana55/CVE-2021-29447-PoC
CVE-2021-29447HIGH18 ene 2026
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC2
Overview of a application that I reversed using the CVE-2015-2291 exploit from the Intel Ethernet Diagnostics Driver (iQVW32.sys) for memory manipulation used in hwid spoofing.
CVE-2015-2291HIGHbajo ataqueransomware18 ene 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
GitHub PoC
Exploitation report for ProFTPD 1.3.5 mod_copy (CVE-2015-3306) lab.
CVE-2015-330618 ene 2026
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.
CVE-2019-905317 ene 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
Comprehensive 100% Unrestricted Technical Analysis of JAGUAR_TOOTH Malware (APT28). High-precision reconstruction of Cisco IOS SNMP exploitation, ROP chaining, and memory-resident espionage tactics by SASTRA_ADI_WIGUNA.
CVE-2017-6742HIGHbajo ataque17 ene 2026
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff
76RIESGO
abrir
GitHub PoC
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known post-exploitation IOCs.
CVE-2025-20393CRITICALbajo ataque16 ene 2026
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RIESGO
abrir
GitHub PoC
faisha1311/React2Shell-CVE-2025-55182-TryHackMe
CVE-2025-55182CRITICALbajo ataqueransomware16 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Kai-One001/React-Router-CVE-2025-61686-
CVE-2025-61686CRITICAL16 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC1
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).
CVE-2018-011416 ene 2026
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.
CVE-2007-244716 ene 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
dkq-k/CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC2
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
CVE-2025-59287CRITICALbajo ataque16 ene 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verifies exploitation by probing sensitive files. Built for learning CVE analysis, not mass exploitation.
CVE-2021-41773HIGHbajo ataqueransomware16 ene 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)
CVE-2026-46368HIGH16 ene 2026
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
41RIESGO
abrir
GitHub PoC
dkq-k/cve-2023-22515-1
CVE-2023-22515CRITICALbajo ataqueransomware16 ene 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
GitHub PoC
End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment
CVE-2013-3900MEDIUMbajo ataque16 ene 2026
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC
CVE-2025-61686复现的dockerfile与poc
CVE-2025-61686CRITICAL15 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
CVE-2025-14847HIGHbajo ataque15 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.