Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
VulnCheck XDB
info-leak
CVE-2021-41773HIGHbajo ataqueransomware27 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
A POC for the recently discovered Qualys bug on COW with XFS
CVE-2026-64600HIGH27 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC2
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.
CVE-2026-63030CRITICALbajo ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-63030 + CVE-2026-60137+poc
CVE-2026-63030CRITICALbajo ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware27 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-52076HIGH27 jul 2026
Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
41RIESGO
abrir
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque27 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC34
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
CVE-2026-42533CRITICAL27 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC1
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
CVE-2026-40000LOW27 jul 2026
Path Traversal Vulnerability in ZTE Blade A75 5G
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
CVE-2026-57973MEDIUM27 jul 2026
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RIESGO
abrir
GitHub PoC10
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
CVE-2026-54121HIGH27 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-50522CRITICALbajo ataque27 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RIESGO
abrir
GitHub PoC
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-9830HIGH27 jul 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RIESGO
abrir
GitHub PoC
yuimamur/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM27 jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
Procjevt/CVE-2026-58138
CVE-2026-58138CRITICAL27 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
CVE-2026-67183HIGH26 jul 2026
TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
41RIESGO
abrir
GitHub PoC4
CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)
CVE-2026-43499HIGH26 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
CVE-2026-66750MEDIUM26 jul 2026
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RIESGO
abrir
GitHub PoC
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
CVE-2026-66749HIGH26 jul 2026
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RIESGO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-warhol-root
CVE-2026-43499HIGH26 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
CVE-2026-66751MEDIUM26 jul 2026
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware26 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware26 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-58644CRITICALbajo ataque26 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
CVE-2026-54121HIGH26 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
anteriorpágina 25 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.