Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
13.235 exploits
GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
CVE-2025-14847HIGHbajo ataque15 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC2
Phantom Signature Attack: An Analysis of the Critical Vulnerability CVE-2025-29774 in the Bitcoin Protocol, SIGHASH_SINGLE Implementation Flaws, and the Mathematical Framework for Private Key Recovery in Lost Cryptocurrency Wallets Enabling Unrestricted Control over BTC Assets
CVE-2025-29774CRITICAL15 ene 2026
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RIESGO
abrir
GitHub PoC
CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to execute arbitrary OS commands via a malicious POST request.
CVE-2025-11953CRITICALbajo ataque15 ene 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC2
WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型的场景下,攻击者可利用此漏洞绕过访问控制、获取敏感数据或实现代码执行。
CVE-2025-14502CRITICAL15 ene 2026
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
48RIESGO
abrir
GitHub PoC1
Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and vulnerable behaviors ethically.
CVE-2025-64155CRITICAL15 ene 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RIESGO
abrir
GitHub PoC
shubtheone/CVE-2021-36260-hikvision
CVE-2021-36260CRITICALbajo ataque15 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
CVE-2025-61686复现的dockerfile与poc
CVE-2025-61686CRITICAL15 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
A comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the Spring4Shell vulnerability (CVE-2022-22965).
CVE-2022-22965CRITICALbajo ataque14 ene 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sandbox to demonstrate JNDI injection, LDAP/RMI referral redirection, and remote code execution (RCE) via the Log4j 2 library.
CVE-2021-44228CRITICALbajo ataqueransomware14 ene 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560
CVE-2021-3560HIGHbajo ataque14 ene 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
encikayelwhitehat-glitch/CVE-2024-3094
CVE-2024-3094CRITICAL14 ene 2026
Xz: malicious code in distributed source
70RIESGO
abrir
GitHub PoC
CVE-2025-64459-hunter
CVE-2025-64459CRITICAL14 ene 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC
🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and efficiently.
CVE-2025-14847HIGHbajo ataque14 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
🛡️ Detect vulnerable MongoDB instances with the high-performance MongoBleed scanner for CVE-2025-14847, ensuring network security and data protection.
CVE-2025-14847HIGHbajo ataque14 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
CVE-2025-9501
CVE-2025-9501CRITICAL14 ene 2026
W3 Total Cache < 2.8.13 - Unauthenticated Command Injection
53RIESGO
abrir
GitHub PoC
Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation
CVE-2025-68428CRITICAL14 ene 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RIESGO
abrir
GitHub PoC
Implementation of the CVE-2023-22809
CVE-2023-22809HIGH14 ene 2026
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
GitHub PoC
0x13-ByteZer0/CVE-2024-21762
CVE-2024-21762CRITICALbajo ataqueransomware13 ene 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
GitHub PoC
POC for the CVE-2025-32462 and CVE-2025-32463 vulnerabilities
CVE-2025-32462LOW13 ene 2026
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
GitHub PoC2
alexcyberx/CVE-2025-14847_Expolit
CVE-2025-14847HIGHbajo ataque13 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
Unauthenticated file upload for Chamilo 1.11.24 and lower
CVE-2023-4220HIGH13 ene 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
GitHub PoC100
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
CVE-2025-43529HIGHbajo ataque13 ene 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
GitHub PoC
Remote code execution for React Server Components 19.0.0 - 19.2.0
CVE-2025-55182CRITICALbajo ataqueransomware13 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Local Priviledge Escalation for Druva
CVE-2020-575213 ene 2026
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
GitHub PoC11
A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtual-to-physical address translation using Superfetch.
CVE-2025-7771HIGH13 ene 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC
React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE) vulnerabilities in Next.js applications (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALbajo ataqueransomware12 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Mr-In4inci3le/CVE-2025-11953-POC-
CVE-2025-11953CRITICALbajo ataque12 ene 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RIESGO
abrir
GitHub PoC
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153812 ene 2026
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC3
Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters
CVE-2025-31324CRITICALbajo ataqueransomware12 ene 2026
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir
GitHub PoC
Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.
CVE-2021-41773HIGHbajo ataqueransomware12 ene 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.