Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC1
Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna
CVE-2023-44487HIGHbajo ataque01 ago 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque01 ago 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and filesystem IOCs, verifies core integrity, and exports evidence. Optional controlled account cleanup; does not remove malware.
CVE-2026-60137MEDIUMbajo ataque01 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
CVE-2026-63563MEDIUM31 jul 2026
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
33RIESGO
abrir
GitHub PoC1
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
CVE-2026-54121HIGH31 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALbajo ataqueransomware31 jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALbajo ataqueransomware31 jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC1
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
CVE-2024-23897CRITICALbajo ataqueransomware31 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC4
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
CVE-2026-54121HIGH31 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
CVE-2026-8347LOW31 jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
28RIESGO
abrir
GitHub PoC
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
CVE-2026-43284HIGH31 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC1
mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
CVE-2026-64531HIGH31 jul 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC
Authenticated Blind OS Command Injection in ClearOS
CVE-2026-67599HIGH31 jul 2026
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RIESGO
abrir
GitHub PoC
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that affects the Survey feature. Unlike CVE-2026-8347 (which involved Express associations), this vulnerability allows an unauthenticated attacker to participate in a restricted/private survey under specific site configurations.
CVE-2026-8337MEDIUM31 jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
33RIESGO
abrir
GitHub PoC10
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC3
LuZe0y/pd2425-cve-2026-43499-config
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
This is N-day patch we releasing by testing our model capabilities
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC4
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Unauthenticated RCE in DBGate <= 7.1.8
CVE-2026-47668CRITICAL31 jul 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALbajo ataque31 jul 2026
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-21858CRITICAL31 jul 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque31 jul 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection engineering, threat hunting, incident response, and Kubernetes security implications.
CVE-2026-43284HIGH31 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC2
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066CRITICAL31 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL31 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
75RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALbajo ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALbajo ataqueransomware31 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALbajo ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
anteriorpágina 21 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.