Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC4
Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2018-18955
CVE-2018-1895521 jul 2026
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
GitHub PoC2
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque20 jul 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC313
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALbajo ataqueransomware20 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL20 jul 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMbajo ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-9242CRITICALbajo ataque20 jul 2026
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RIESGO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE (CVE-2026-63030)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
0x00phantom-hat/CVE-2026-5029-Exploit
CVE-2026-5029HIGH20 jul 2026
RCE in Code Runner MCP Server
41RIESGO
abrir
GitHub PoC
Detection script for CVE-2026-11374
CVE-2026-11374CRITICAL20 jul 2026
Account Takeover via Predictable SSO Ticket Generation
48RIESGO
abrir
GitHub PoC
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2026-60121, CVE-2026-61498 - Draft
CVE-2026-60121CRITICAL20 jul 2026
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
48RIESGO
abrir
GitHub PoC
CVE-2026-4858 research
CVE-2026-4858HIGH20 jul 2026
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
21RIESGO
abrir
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMbajo ataque20 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC5
PoC for CVE-2026-12191
CVE-2026-12191HIGH20 jul 2026
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49086MEDIUM20 jul 2026
Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour
33RIESGO
abrir
GitHub PoC1
WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
TheLiimbo/CVE-2026-51992
CVE-2026-5199220 jul 2026
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALbajo ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC1
PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange headers, hijacking the tool route's exec: sink for RCE. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49042HIGH20 jul 2026
Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
41RIESGO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Apache Syncope: User self-service privilege escalation
CVE-2026-62183CRITICAL20 jul 2026
Apache Syncope: User self-service privilege escalation
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
anteriorpágina 33 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.