Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC1
CVE-2026-70559
CVE-2026-70559HIGH07 ago 2026
Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
41RIESGO
abrir
GitHub PoC46
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
Shams-Ul-Mehmood/CVE-2021-3156-Project
CVE-2021-3156HIGHbajo ataque07 ago 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC1
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
CVE-2026-64561HIGH07 ago 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RIESGO
abrir
GitHub PoC1
Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration, interactive shell, payload obfuscation, and professional reporting (JSON/HTML/PDF). Authorized testing only.
CVE-2025-55182CRITICALbajo ataqueransomware07 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-64638 - Draft or TODO
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
CVE-2026-71554MEDIUM07 ago 2026
h2: Duplicate Host header could facilitate request smuggling
33RIESGO
abrir
GitHub PoC
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass
CVE-2026-55957HIGH07 ago 2026
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
41RIESGO
abrir
GitHub PoC3
Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
0init/CVE-2026-45185
CVE-2026-45185CRITICAL07 ago 2026
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
48RIESGO
abrir
GitHub PoC
Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.
CVE-2018-1676307 ago 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC1
CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin Creation → Site Compromise. CVSS 8.1
CVE-2026-11961HIGH07 ago 2026
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque07 ago 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-64638
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
ZSecur1ty/XSS2Shell-CVE-2026-64638
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
CVE-2026-64638
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC5
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
CVE-2026-64638HIGH07 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC7
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel
CVE-2026-43499HIGH07 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC56
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
CVE-2026-55040CRITICALbajo ataque06 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
78RIESGO
abrir
GitHub PoC1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
CVE-2026-65058MEDIUM06 ago 2026
Trezor Safe improper security check in on-device display
13RIESGO
abrir
GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
CVE-2026-41293CRITICAL06 ago 2026
Apache Tomcat: HTTP/2 request headers not validated
48RIESGO
abrir
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
CVE-2026-66492MEDIUM06 ago 2026
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RIESGO
abrir
GitHub PoC
tfawnies/CVE-2026-64633
CVE-2026-64633CRITICAL06 ago 2026
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RIESGO
abrir
GitHub PoC1
woshidashabi1126/CVE-2026-70553-PoC
CVE-2026-70553CRITICAL06 ago 2026
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RIESGO
abrir
GitHub PoC5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
CVE-2026-58048CRITICAL06 ago 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RIESGO
abrir
GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
CVE-2026-49268HIGH06 ago 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RIESGO
abrir
GitHub PoC2
CVE-2026-0163 Exploit
CVE-2026-0163CRITICAL06 ago 2026
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RIESGO
abrir
GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
CVE-2018-7600CRITICALbajo ataqueransomware06 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH06 ago 2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
anteriorpágina 13 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.