Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
77.866 exploits
GitHub PoC
Technical analysis of the cPanel/WHM auth bypass
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC
CVE-2026-63030 - WordPress Core Pre-Auth RCE Mass Exploit
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗GitHub PoC★ 8
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 14
Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 5
Pre-auth RCE in WordPress Core via REST API batch route confusion + WP_Query SQLi (CVE-2026-63030 / CVE-2026-60137). Detection PoC.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 4
Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗GitHub PoC
Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
tcyph3r/wp2shell-cve-2026-63030-root-cause
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 2
wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗GitHub PoC
Advisory for CVE-2026-51385. Needed to publish it as GRAPHIFY hasnt recognized the advisory neither publish it, and MITRE assigned CVE-2026-51385, this is the advisory for it.
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v
33RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.
setup-php: Command Injection in Repository-Derived PHP Version Resolution
33RIESGO
abrir ↗GitHub PoC★ 15
Use CVE-2026-43499 to disable SELinux on Android
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 37
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 6
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
akash-osmsec/CVE-2026-44262-
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RIESGO
abrir ↗GitHub PoC★ 7
CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
CVE-2026-43499 reproduce in Xiaomi 17T. (kernelsu incomplete)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗GitHub PoC
Hunt-Benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri
Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
41RIESGO
abrir ↗GitHub PoC★ 5
Use CVE-2026-43074 to disable SELinux on Android (Linux 6.6/6.12)
eventpoll: defer struct eventpoll free to RCU grace period
41RIESGO
abrir ↗VulnCheck XDB
info-leak
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir ↗GitHub PoC
CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 102
CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.