Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.260exploits catalogados
36.452CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.050GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
77.866 exploits
GitHub PoC★ 3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RIESGO
abrir ↗GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗GitHub PoC★ 1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
Microsoft Defender Elevation of Privilege Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
Windows Kernel Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
CVE-2026-33017, vuln in langflow.
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RIESGO
abrir ↗Exploit-DB
NanaZip 6.5 - DoS
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RIESGO
abrir ↗GitHub PoC
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Gitea Docker image trusts spoofable reverse-proxy headers by default
75RIESGO
abrir ↗GitHub PoC
POC for CVE-2026-41042
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RIESGO
abrir ↗Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
Infinite loop on invalid input in golang.org/x/text
41RIESGO
abrir ↗GitHub PoC
katranSefa/CVE-2026-13714
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RIESGO
abrir ↗Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RIESGO
abrir ↗GitHub PoC
CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender
Site isolation issue in the Graphics component
33RIESGO
abrir ↗GitHub PoC
CVE-2026-15826, CVE-2026-15748
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RIESGO
abrir ↗Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗GitHub PoC
CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)
Use-after-free in the Graphics: ImageLib component
48RIESGO
abrir ↗GitHub PoC★ 5
A poc and write-up for CVE-2026-40345
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RIESGO
abrir ↗GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
Cross-Site Request Forgery (CSRF) in GitLab
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.