Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque23 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
CVE-2026-58057LOW23 jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
CVE-2026-0770CRITICALbajo ataque23 jul 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
CVE-2025-2783HIGHbajo ataque23 jul 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-43451MEDIUMbajo ataque23 jul 2026
NTLM Hash Disclosure Spoofing Vulnerability
85RIESGO
abrir
GitHub PoC5
soralis0912/CVE-2026-43499-aristotle-apk
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2025-55182-react2shell_reproduction
CVE-2025-55182CRITICALbajo ataqueransomware23 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
FernandoCassioDev/CVE-2015-1328
CVE-2015-132823 jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CVE-2026-45132CRITICAL23 jul 2026
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RIESGO
abrir
GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL22 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC3
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip
CVE-2026-14266HIGH22 jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque22 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC1
Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.
CVE-2026-41089CRITICAL22 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC12
CVE-2026-46331 and CVE-2026-43503
CVE-2026-46331HIGH22 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque22 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
VulnCheck XDB
local
CVE-2023-2640HIGH22 jul 2026
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir
GitHub PoC1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
CVE-2026-16540HIGH22 jul 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RIESGO
abrir
GitHub PoC17
CVE-2026-43499 PoC Scanner
CVE-2026-43499HIGH22 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
Vulnerabilidad en NGINX
CVE-2026-42533CRITICAL22 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2026-50522 - Draft
CVE-2026-50522CRITICALbajo ataque22 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
CVE-2026-6330MEDIUM22 jul 2026
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RIESGO
abrir
VulnCheck XDB
local
CVE-2023-32629HIGH22 jul 2026
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created or supported by Check Point and should be used at your own risk.
CVE-2026-16232CRITICALbajo ataque22 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability detected during a target network scan.
CVE-2012-1823CRITICALbajo ataque22 jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC15
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC20
CVE-2026-64600
CVE-2026-64600HIGH22 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC
ThorVG NULL pointer dereference via malformed SVG — AFL++ fuzzing writeup
CVE-2026-45729MEDIUM22 jul 2026
ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malformed input
33RIESGO
abrir
anteriorpágina 30 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.