Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
77.866 exploits
GitHub PoC
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RIESGO
abrir ↗GitHub PoC
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RIESGO
abrir ↗GitHub PoC★ 1
Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
48RIESGO
abrir ↗GitHub PoC
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RIESGO
abrir ↗GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC★ 3
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 23
基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 6
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir ↗GitHub PoC
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
33RIESGO
abrir ↗GitHub PoC
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RIESGO
abrir ↗GitHub PoC★ 2
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE, in-process machine key theft, and the artifacts each variant leaves behind. SharePoint 2016, 2019, and Subscription Edition. CVE-2026-50522, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644.
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RIESGO
abrir ↗GitHub PoC
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RIESGO
abrir ↗GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RIESGO
abrir ↗GitHub PoC
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
33RIESGO
abrir ↗GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RIESGO
abrir ↗GitHub PoC★ 39
CVE-2026-50522 PoC
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
33RIESGO
abrir ↗GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC
Security Advisory for CVE-2026-51564
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RIESGO
abrir ↗GitHub PoC★ 5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RIESGO
abrir ↗GitHub PoC★ 2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir ↗GitHub PoC★ 17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Auth Bypass in inetutils-telnetd
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.