Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC
1-day exploit for CVE-2026-45258
Multiple vulnerabilities in the sound(4) mmap path
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC★ 1
PoC de CVE-2026-7473: bypass de decapsulacion de tunel en Arista EOS.
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
63RIESGO
abrir ↗GitHub PoC★ 6
watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC
1-day exploit for CVE-2026-49417
Multiple vulnerabilities in the sound(4) mmap path
41RIESGO
abrir ↗GitHub PoC★ 6
CVE-2026-25089 - Fortinet FortiSandbox
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir ↗GitHub PoC
Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
CVE-2026-50751 Check Point IKEv1 vulnerability scanner
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC
PoC de CVE-2026-20245: escalada de privilegios en Cisco SD-WAN. Solo fines educativos y pruebas autorizadas.
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
76RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-10520 - Ivanti Sentry Pre-Auth OS Command Injection Mass Scanner
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir ↗GitHub PoC★ 1
PoC de CVE-2026-50751: bypass de autenticacion IKEv1 en Check Point Remote/Mobile Access.
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC
CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 3
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
48RIESGO
abrir ↗GitHub PoC
WORDPRESS
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RIESGO
abrir ↗GitHub PoC★ 2
Validation report for the RoguePlanet Microsoft Defender PoC in a controlled Windows 11 lab environment, including build notes, Defender detection results, risk assessment, and mitigation recommendations.
Microsoft Defender Elevation of Privilege Vulnerability
46RIESGO
abrir ↗GitHub PoC
CVE-2026-44963 - Draft - Veeam
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
48RIESGO
abrir ↗GitHub PoC
Saku0512/CVE-2026-48732-poc
Warp: Remote SSH cwd can lead to unauthorized remote command execution
41RIESGO
abrir ↗GitHub PoC★ 1
GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes vulnerability assessment, detection guidance, technical analysis, indicators of compromise (IOCs), and remediation validation resources for security teams and defenders.
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RIESGO
abrir ↗GitHub PoC★ 3
PoC de CVE-2026-11645: lectura/escritura fuera de limites en Chrome V8 (CVSS 8.8).
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
71RIESGO
abrir ↗GitHub PoC
Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗GitHub PoC
adamshaikhma/CVE-2026-11645
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
71RIESGO
abrir ↗VulnCheck XDB
local
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.