Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
CVE-2026-14856MEDIUM28 jul 2026
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RIESGO
abrir
GitHub PoC
0xdak/CVE-2025-71389_exploit
CVE-2025-71389CRITICAL28 jul 2026
Cal.com before 5.9.9 Remote Code Execution via RSC
48RIESGO
abrir
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
CVE-2026-65761CRITICAL28 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
48RIESGO
abrir
GitHub PoC1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
CVE-2026-9198CRITICALbajo ataque28 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
CVE-2026-16232CRITICALbajo ataque28 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
CVE-2026-58586CRITICAL28 jul 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RIESGO
abrir
GitHub PoC10
KSU installer for supported firmware with CVE-2026-43499
CVE-2026-43499HIGH28 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
CVE-2026-64600HIGH28 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH28 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque28 jul 2026
Incorrect Authorization in Graphics
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-8206CRITICAL28 jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALbajo ataque28 jul 2026
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RIESGO
abrir
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
CVE-2026-59891CRITICAL28 jul 2026
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
48RIESGO
abrir
GitHub PoC
Microsoft SharePoint CVE-2026-50522
CVE-2026-50522CRITICALbajo ataque28 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
A PoC for CVE-2026-64725
CVE-2026-64725HIGH28 jul 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RIESGO
abrir
GitHub PoC
Clickbait. The CVE is AI slop.
CVE-2026-5130228 jul 2026
23RIESGO
abrir
GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-65893HIGH28 jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RIESGO
abrir
GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
CVE-2011-252328 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
CVE-2020-7961CRITICALbajo ataque28 jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC3
cve-2026-61511
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
GitHub PoC
CVE-2026-61511 - Draft or Todo
CVE-2026-61511CRITICAL28 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
GitHub PoC
Phucc29/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware27 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
yuimamur/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM27 jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
CVE-2021-41773HIGHbajo ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2026-60137_CVE-2026-63030
CVE-2026-60137MEDIUMbajo ataque27 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
PoC and analysis of CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Procjevt/CVE-2026-58138
CVE-2026-58138CRITICAL27 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
anteriorpágina 24 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.