Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH09 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware09 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.
CVE-2017-8464HIGHbajo ataque09 ago 2026
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC6
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)
CVE-2026-34910CRITICALbajo ataque09 ago 2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RIESGO
abrir
GitHub PoC1
POC 4 CVE-2026-15038
CVE-2026-15038CRITICAL09 ago 2026
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
48RIESGO
abrir
GitHub PoC
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials.
CVE-2026-63030CRITICALbajo ataque09 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware09 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.
CVE-2025-3248CRITICALbajo ataqueransomware09 ago 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
GitHub PoC
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB
CVE-2025-59528CRITICAL09 ago 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC1
CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.
CVE-2026-69084CRITICAL09 ago 2026
SiYuan before v3.7.3 SQL Injection via searchEmbedBlock
63RIESGO
abrir
GitHub PoC
Linux 内核升级指南 - 修复 CVE-2026-64561
CVE-2026-64561HIGH08 ago 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RIESGO
abrir
GitHub PoC
sandimfz/CVE-2024-23692
CVE-2024-23692CRITICALbajo ataqueransomware08 ago 2026
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RIESGO
abrir
GitHub PoC6
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
teamcity teamcity-CVE-2026-63077 exploitation pcap
CVE-2026-63077CRITICALbajo ataque08 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
98RIESGO
abrir
GitHub PoC1
yogaGymn/XSS2Shell-CVE-2026-64638
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC4
WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab
CVE-2026-63030CRITICALbajo ataque08 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
A Linux kernel local privilege escalation affecting the XFS filesystem copy-on-write (CoW) path.
CVE-2026-64600HIGH08 ago 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC1
🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing
CVE-2026-64561HIGH08 ago 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RIESGO
abrir
GitHub PoC
Saku0512/CVE-2026-71557-poc
CVE-2026-71557MEDIUM08 ago 2026
go-git: Malicious reference names may modify files outside the reference storage
33RIESGO
abrir
GitHub PoC
CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass exploitation tool with interactive shell, multi-threading, and real-time result logging.
CVE-2026-63077CRITICALbajo ataque08 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
98RIESGO
abrir
GitHub PoC
Write-up do Sudo Agent CTF (TryHackMe), com enumeração, exploração web, esteganografia, SSH e privilege escalation via CVE-2019-14287.
CVE-2019-1428708 ago 2026
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC18
Root your Galaxy using CVE-2026-43499
CVE-2026-43499HIGH08 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter
CVE-2026-18953MEDIUM08 ago 2026
Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
33RIESGO
abrir
GitHub PoC1
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
CVE-2026-64638 (XSS2shell) POC.
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
mohwahyudi/poc-CVE-2026-64638-
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2026-64638
CVE-2026-64638HIGH08 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
anteriorpágina 11 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.