Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALbajo ataqueransomware03 ago 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-
CVE-2026-6666MEDIUM03 ago 2026
PgBouncer crash in kill_pool_logins_server_error
33RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-68771_exploit
CVE-2026-68771CRITICAL03 ago 2026
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
48RIESGO
abrir
GitHub PoC
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
CVE-2026-45585MEDIUM03 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
CVE-2026-16723CRITICAL03 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque03 ago 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC32
villager1314/CVE-2026-64560-Analysis
CVE-2026-64560HIGH03 ago 2026
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
CVE-2026-11104MEDIUM03 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
CVE-2026-3891CRITICAL03 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 ago 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RIESGO
abrir
GitHub PoC2
Kangaroo is a exploit built on CVE-2026-32746. i made this for security researchers, IT professionals, DevOps. so they can understand it better. DO NOT USE THIS FOR ILLEGAL USE, IF YOU DO... YOU MAY BE SUBJECT TO ARREST, AND FINES.
CVE-2026-32746CRITICAL02 ago 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir
GitHub PoC20
the CVE-2026-43499 by iqooneo11
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC3
CVE-2026-43499 for the Meta Quest
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC3
WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.
CVE-2026-63030CRITICALbajo ataque02 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC9
Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.
CVE-2026-57827CRITICAL02 ago 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir
GitHub PoC1
TryHackMe Dirty Frag (CVE-2026-43284) — Linux LPE writeup
CVE-2026-43284HIGH02 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware02 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque02 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PHP payloads.
CVE-2026-49049HIGH02 ago 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque02 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque02 ago 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC170
Jailbreak supported Google Pixel phones with CVE-2026-43499
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2026-13714CRITICAL02 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RIESGO
abrir
GitHub PoC2
A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying the repository’s configured approval gates.
CVE-2026-58424HIGH02 ago 2026
Permanent Fork PR Workflow Approval Gate Bypass
41RIESGO
abrir
GitHub PoC
VMware vCenter Server CVE-2021-21972 (RCE) — vulnerability analysis, detection, and mitigation
CVE-2021-21972CRITICALbajo ataqueransomware02 ago 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque02 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.
CVE-2021-44228CRITICALbajo ataqueransomware02 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.
CVE-2026-9806MEDIUM02 ago 2026
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
33RIESGO
abrir
GitHub PoC
CVE-2026-9811 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).
CVE-2026-9811MEDIUM02 ago 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s
33RIESGO
abrir
anteriorpágina 19 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.