Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
13.264 exploits
GitHub PoC3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
CVE-2025-52694CRITICAL12 ene 2026
Execution of arbitrary SQL commands
75RIESGO
abrir
GitHub PoC
React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE) vulnerabilities in Next.js applications (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALbajo ataqueransomware12 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
js2py <= 0.74 sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM11 ene 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RIESGO
abrir
GitHub PoC2
CVE-2025-55182漏洞检测工具
CVE-2025-55182CRITICALbajo ataqueransomware11 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.
CVE-2025-8088HIGHbajo ataque11 ene 2026
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC3
rimbadirgantara/CVE-2025-52691-poc
CVE-2025-52691CRITICALbajo ataqueransomware11 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC
sahar042/CVE-2025-14847
CVE-2025-14847HIGHbajo ataque11 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC1
PoC Authentication Bypass to RCE to Exploit CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware11 ene 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
Original security research into container boundary weaknesses. Published: OCI hook privilege escalation in rootless Podman deployments (CVE-2025-23266).
CVE-2025-23266CRITICAL10 ene 2026
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RIESGO
abrir
GitHub PoC2
A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS) vulnerabilities.
CVE-2024-6297CRITICAL10 ene 2026
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
48RIESGO
abrir
GitHub PoC
Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.
CVE-2024-5153CRITICAL10 ene 2026
Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion
48RIESGO
abrir
GitHub PoC
comerc/CVE-2025-68664
CVE-2025-68664CRITICAL10 ene 2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
53RIESGO
abrir
GitHub PoC
mooowu/cve-2025-55182-poc
CVE-2025-55182CRITICALbajo ataqueransomware10 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Unauthenticated RCE exploit for XWiki CVE-2025-24893 via Groovy script injection
CVE-2025-24893CRITICALbajo ataque09 ene 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
CVE-2023-38831 - WinRAR
CVE-2023-38831HIGHbajo ataqueransomware09 ene 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
GitHub PoC1
CVE-2025-14847 explaination and lab
CVE-2025-14847HIGHbajo ataque09 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC1
CVE-2015-3224 Exploit - Rails Web Console RCE
CVE-2015-322409 ene 2026
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
GitHub PoC
A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation
CVE-2023-2968909 ene 2026
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir
GitHub PoC
Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE via service backdoors (CVE-2011-2523), and cryptographic credential recovery.
CVE-2011-252309 ene 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.
CVE-2023-23397CRITICALbajo ataque09 ene 2026
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
Auto exploitation tool for CVE-2024-24401
CVE-2024-24401CRITICAL08 ene 2026
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl
60RIESGO
abrir
GitHub PoC
CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure
CVE-2025-14847HIGHbajo ataque08 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
GitHub PoC1
flame-11/CVE-2025-54068-livewire
CVE-2025-54068CRITICALbajo ataque08 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
GitHub PoC
Authenticated RCE for Webmin 1.9.0
CVE-2019-962408 ene 2026
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RIESGO
abrir
GitHub PoC
CVE-2021-4379 Enumeration Tools
CVE-2021-43798HIGHbajo ataque08 ene 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC19
watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691
CVE-2025-52691CRITICALbajo ataqueransomware08 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
GitHub PoC
alxsourin/Helpdesk-Telecom-CVE-2025-64459
CVE-2025-64459CRITICAL08 ene 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC31
CVE-2025-55182-bypass-waf
CVE-2025-55182CRITICALbajo ataqueransomware08 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
Crime2/poc-CVE-2025-38352
CVE-2025-38352HIGHbajo ataque08 ene 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RIESGO
abrir
GitHub PoC24
CVE-2025-68428 Proof of Concept
CVE-2025-68428CRITICAL08 ene 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.