Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
13.264 exploits
GitHub PoC
Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)
CVE-2025-68613CRITICALbajo ataque22 ene 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
GitHub PoC
Dirty Cow exploit - CVE-2016-5195
CVE-2016-5195HIGHbajo ataque22 ene 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHbajo ataque22 ene 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
CVE-2024-9932CRITICAL22 ene 2026
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC1
A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.
CVE-2012-1823CRITICALbajo ataque22 ene 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP webshell and achieve remote command execution without authentication, including OS detection and an interactive shell.
CVE-2023-51409CRITICAL22 ene 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RIESGO
abrir
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute arbitrary PHP code, write a web shell to the uploads directory, detect the target operating system, and achieve remote command execution via an interactive shell.
CVE-2024-50498CRITICAL22 ene 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RIESGO
abrir
GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-61686CRITICAL21 ene 2026
React Router has Path Traversal in File Session Storage
53RIESGO
abrir
GitHub PoC
afifudinmtop/CVE-2021-21425
CVE-2021-21425CRITICAL21 ene 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RIESGO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2017-7921CRITICALbajo ataque21 ene 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHbajo ataqueransomware21 ene 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
CVE-2019-10149CRITICALbajo ataque21 ene 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
Final Project in Fundamental network security,POC CVE-202438063
CVE-2024-38063CRITICAL21 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC2
This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771
CVE-2025-7771HIGH21 ene 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RIESGO
abrir
GitHub PoC
CybersRMUTL/CVE-2019-9193-Postgresql-RCE
CVE-2019-919321 ene 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC1
InfoSecAntara/CVE-2025-14847-MongoDB
CVE-2025-14847HIGHbajo ataque21 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
SMBv1: CVE-2017-0143, gravedad 8.8, de ejecucion remota de codigo (RCE), en Windows con SMBv1 (ms17-010)
CVE-2017-0143HIGHbajo ataqueransomware21 ene 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC2
海康威视RCE漏洞 批量检测和利用工具
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
CVE-2024-38476CRITICAL21 ene 2026
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RIESGO
abrir
GitHub PoC
MOVEit Transfer 2023 mass data breach (CVE-2023-34362)
CVE-2023-34362CRITICALbajo ataqueransomware21 ene 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2021-36260CRITICALbajo ataque21 ene 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2025-55182(命令执行、反弹shell、注入内存马)
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware20 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.
CVE-2025-14847HIGHbajo ataque20 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC
Cacti exploit
CVE-2024-25641CRITICAL20 ene 2026
Cacti RCE vulnerability when importing packages
85RIESGO
abrir
GitHub PoC5
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
CVE-2025-54068CRITICALbajo ataque20 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC
SSP H3
CVE-2024-38063CRITICAL20 ene 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.
CVE-2011-252320 ene 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
CVE-2026-23744CRITICAL20 ene 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.