Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
CVE-2026-64531HIGH29 jul 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC
Pravin761/CVE-2026-54107
CVE-2026-54107HIGH29 jul 2026
Windows Win32k Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-41773HIGHbajo ataqueransomware29 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC15
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
CVE-2026-57827CRITICAL29 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir
GitHub PoC
manfredgabriel/cve-2021-41773-lab
CVE-2021-41773HIGHbajo ataqueransomware29 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
CVE-2026-58025MEDIUM29 jul 2026
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-57811-Proof-of-Concept
CVE-2026-57811CRITICAL29 jul 2026
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
28RIESGO
abrir
GitHub PoC23
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-61511-POC
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36104CRITICAL29 jul 2026
Apache OFBiz: Path traversal leading to a RCE
85RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-50522-Proof-of-Concept
CVE-2026-50522CRITICALbajo ataque29 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-45746CRITICAL29 jul 2026
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RIESGO
abrir
GitHub PoC5
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVE-2026-49176HIGH29 jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-2586 — Eclipse GlassFish EL injection to RCE
CVE-2026-2586CRITICAL29 jul 2026
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RIESGO
abrir
GitHub PoC
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
CVE-2026-52134CRITICAL29 jul 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RIESGO
abrir
GitHub PoC1
CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)
CVE-2026-43499HIGH29 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
CVE-2026-66066
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC
CamilleGR/CVE-2026-73292
CVE-2026-73292HIGH29 jul 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque28 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54121HIGH28 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
CVE-2026-59891CRITICAL28 jul 2026
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
48RIESGO
abrir
GitHub PoC1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
CVE-2026-9198CRITICALbajo ataque28 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque28 jul 2026
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-8206CRITICAL28 jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque28 jul 2026
Incorrect Authorization in Graphics
71RIESGO
abrir
GitHub PoC4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH28 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Clickbait. The CVE is AI slop.
CVE-2026-5130228 jul 2026
23RIESGO
abrir
GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
CVE-2026-14856MEDIUM28 jul 2026
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RIESGO
abrir
GitHub PoC1
A PoC for CVE-2026-64725
CVE-2026-64725HIGH28 jul 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RIESGO
abrir
anteriorpágina 23 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.