Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.275exploits catalogados
36.462CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALbajo ataque29 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
CVE-2024-49138HIGHbajo ataque29 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALbajo ataqueransomware28 ago 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC1
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALbajo ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALbajo ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALbajo ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALbajo ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALbajo ataqueransomware28 ago 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
CVE-2026-73570HIGHbajo ataque28 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RIESGO
abrir
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware28 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
CVE-2026-65643 - Draft or TODO
CVE-2026-65643HIGH28 ago 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque28 ago 2026
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL28 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 ago 2026
ipc: limit next_id allocation to the valid ID range
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque28 ago 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALbajo ataqueransomware28 ago 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
GitHub PoC
CVE-2026-66384 - Draft or TODO
CVE-2026-66384MEDIUMbajo ataque28 ago 2026
Authenticated users may write data outside the intended Docker cache path
63RIESGO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-19295
CVE-2026-19295CRITICAL28 ago 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RIESGO
abrir
GitHub PoC
Testing CVE-2026-70463 by Fyyre
CVE-2026-70463HIGH28 ago 2026
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 ago 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL28 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque28 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALbajo ataqueransomware28 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
poc and yara rules
CVE-2025-59528CRITICAL28 ago 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALbajo ataque28 ago 2026
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
CVE-2024-23897CRITICALbajo ataqueransomware28 ago 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
CVE-2020-14882CRITICALbajo ataque27 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.