Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
71.836 exploits
GitHub PoC★ 1
CVE-2026-23918 Apache mod_http2 Double-Free Detector
Apache HTTP Server: http2: double free and possible RCE on early reset
53RIESGO
abrir ↗Metasploit300
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir ↗GitHub PoC
Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
36RIESGO
abrir ↗GitHub PoC
borahll/CVE-2021-21220
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to po
100RIESGO
abrir ↗GitHub PoC★ 1
cve-2026-41940 cPanel/WHM Authentication Bypass - Detection Artifact Generator
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 2
Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut
43RIESGO
abrir ↗GitHub PoC★ 2
Math.js Expression Parser RCE
Math.js: Unsafe object property setter in mathjs
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-31431 Copy Fail
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
CVE-2026-31431, AKA Copy Fail, can be mitigated in one-line with bpftrace
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
julichaan/CVE-2026-31431-python-copyfail-POC
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC★ 3
One-liner Python LPE for CVE-2026-31431 (CopyFail2). No compilation, no dependencies beyond Python+OpenSSL. Just curl | python3 and get root on Linux 6.5+.
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
adilkurtulmus/linux-copy-fail-CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
Vulnerability Research and Exploit for CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗Exploit-DB
Bludit CMS 3.18.4 - RCE
Remote Code Execution via Unrestricted File Upload in Bludit
41RIESGO
abrir ↗Exploit-DB
ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)
ThingsBoard < v4.2.1 SVG Image SSRF
33RIESGO
abrir ↗GitHub PoC★ 171
Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572)
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo
41RIESGO
abrir ↗GitHub PoC
CVE-2026-44590 - Sherlock <= v0.16.0 - RCE via pull_request_target Injection → Supply Chain Compromise
Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml
28RIESGO
abrir ↗GitHub PoC★ 33
CVE-2026-23631 (DarkReplica) Redis Exploit
redis-server Lua use-after-free may allow remote code execution
33RIESGO
abrir ↗Exploit-DB
NocoBase 2.0.27 - VM Sandbox Escape
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.