Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.232exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
GitHub PoC
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
CVE-2026-14662HIGH01 sep 2026
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41RIESGO
abrir
GitHub PoC1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
CVE-2026-82592CRITICAL01 sep 2026
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RIESGO
abrir
GitHub PoC7
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
CVE-2026-82329CRITICALbajo ataque01 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
Exploit-DB
Grav CMS 2.0.7 - RCE
CVE-2026-65008CRITICALwebappsmultiple01 sep 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RIESGO
abrir
GitHub PoC2
Keycloak reset-credentials flow bypass
CVE-2026-18963CRITICAL01 sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware01 sep 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Wolf CMS 0.8.3.1 - RCE v
CVE-2026-67206HIGHwebappsmultiple01 sep 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RIESGO
abrir
GitHub PoC
pervinzahidli/CVE-2026-75855
CVE-2026-75855HIGH01 sep 2026
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque01 sep 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL01 sep 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
CVE-2026-82221HIGH01 sep 2026
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RIESGO
abrir
GitHub PoC1
Poc of CVE-2026-13753
CVE-2026-13753HIGH01 sep 2026
Certain HP DeskJet All in One – Potential Information Disclosure
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware01 sep 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware01 sep 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque01 sep 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
CVE-2026-82329 - Draft or TODO
CVE-2026-82329CRITICALbajo ataque01 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RIESGO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL31 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RIESGO
abrir
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque31 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 ago 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RIESGO
abrir
GitHub PoC1
Public PoC for CVE-2026-82222
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC1
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
CVE-2026-78905HIGH30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RIESGO
abrir
GitHub PoC2
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
CVE-2026-78904CRITICAL30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
48RIESGO
abrir
GitHub PoC1
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.