Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC2
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CVE-2026-63223CRITICAL03 ago 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RIESGO
abrir
GitHub PoC
siboy17/CVE-2022-21907-http.sys
CVE-2022-21907CRITICAL03 ago 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
CVE-2026-45585MEDIUM03 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
CVE-2026-54121HIGH03 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALbajo ataqueransomware03 ago 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
CVE-2026-11104MEDIUM03 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
CVE-2026-3891CRITICAL03 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque03 ago 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-53576CRITICAL03 ago 2026
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RIESGO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
CVE-2026-9998HIGH03 ago 2026
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RIESGO
abrir
GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
CVE-2026-60137MEDIUMbajo ataque03 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11101-HTTP-Cache-Poisoning-via-Unkeyed-Query-Parameter
CVE-2026-11101MEDIUM03 ago 2026
Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-ori
33RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
CVE-2026-9999HIGH03 ago 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RIESGO
abrir
GitHub PoC
Procjevt/CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque03 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking
CVE-2026-11102HIGH03 ago 2026
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to e
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-8888-Printer-Firmware-Unsigned-Update-via-HTTP
CVE-2026-8888HIGH03 ago 2026
CVE-2026-8888
41RIESGO
abrir
GitHub PoC
CVE-2026-17583 - Draft
CVE-2026-17583HIGH03 ago 2026
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-49049HIGH03 ago 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL03 ago 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC10
proof-of-concept scripts for 2 unauthenticated RCEs in Samba (CVE-2026-4408 & CVE-2026-4480) and local privilege escalation in TelnetD (CVE-2026-28372)
CVE-2026-4408CRITICAL03 ago 2026
Samba: remote code execution in samr
48RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass
CVE-2026-11103HIGH03 ago 2026
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9090-Modbus-TCP-Write-to-Read-Only-Coils-via-Function-Code-Spoofing
CVE-2026-9090CRITICAL03 ago 2026
CVE-2026-9090
48RIESGO
abrir
GitHub PoC
Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)
CVE-2026-63720HIGH03 ago 2026
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL03 ago 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
local
CVE-2022-22706HIGHbajo ataque03 ago 2026
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-68771_exploit
CVE-2026-68771CRITICAL03 ago 2026
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
48RIESGO
abrir
anteriorpágina 18 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.