Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.900 exploits
GitHub PoC4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
CVE-2026-18649HIGH06 ago 2026
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RIESGO
abrir
GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
CVE-2018-7600CRITICALbajo ataqueransomware06 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
CVE-2026-49268HIGH06 ago 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-69098_exploit
CVE-2026-69098CRITICAL06 ago 2026
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RIESGO
abrir
GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
CVE-2026-67598CRITICAL06 ago 2026
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RIESGO
abrir
GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
CVE-2026-18556HIGHbajo ataque06 ago 2026
Unauthenticated administrative account takeover
71RIESGO
abrir
GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
CVE-2026-41293CRITICAL06 ago 2026
Apache Tomcat: HTTP/2 request headers not validated
48RIESGO
abrir
GitHub PoC5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
CVE-2026-58048CRITICAL06 ago 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RIESGO
abrir
GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
CVE-2026-52886MEDIUM06 ago 2026
Notepad++: session.xml backupFilePath starts_with Bypass
33RIESGO
abrir
GitHub PoC2
CVE-2026-0163 Exploit
CVE-2026-0163CRITICAL06 ago 2026
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RIESGO
abrir
GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
CVE-2019-697706 ago 2026
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
35RIESGO
abrir
GitHub PoC1
woshidashabi1126/CVE-2026-70553-PoC
CVE-2026-70553CRITICAL06 ago 2026
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RIESGO
abrir
GitHub PoC
hasan8babiker/CVE-2024-6387
CVE-2024-6387HIGH06 ago 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC
xuwu-xuwu/CVE-2026-68004
CVE-2026-68004CRITICAL05 ago 2026
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP pub
48RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2023-6553
CVE-2023-6553CRITICAL05 ago 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-44024_exploit
CVE-2026-44024CRITICAL05 ago 2026
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RIESGO
abrir
GitHub PoC822
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
rmhowe425/PoC-CVE-2026-9198
CVE-2026-9198CRITICALbajo ataque05 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC12
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430MEDIUM05 ago 2026
CVE-2026-15430
33RIESGO
abrir
GitHub PoC
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.
CVE-2026-54917HIGH05 ago 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
41RIESGO
abrir
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALbajo ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
CVE-2025-32432CRITICALbajo ataque05 ago 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
CVE-2026-58062CRITICAL05 ago 2026
Stapled OCSP response accepted without binding to the checked certificate
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque05 ago 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 ago 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware05 ago 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque05 ago 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 ago 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RIESGO
abrir
anteriorpágina 14 / 2597siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.