Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.
CVE-2026-9271MEDIUM17 jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RIESGO
abrir
GitHub PoC2
2932796375github/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)
CVE-2023-23752MEDIUMbajo ataque17 jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
hg0434hongzh0/CVE-2026-14266
CVE-2026-14266HIGH17 jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque17 jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
CVE-2026-38526 Exploit | by infrar3d
CVE-2026-38526CRITICAL17 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
jaf0rk/CVE-2026-14431
CVE-2026-14431HIGH17 jul 2026
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
41RIESGO
abrir
GitHub PoC
tungduongNT/CVE-2014-0160.
CVE-2014-0160HIGHbajo ataque17 jul 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC44
CVE-2026-50416: Windows 11 KASLR bypass
CVE-2026-50416LOW17 jul 2026
Win32k Information Disclosure Vulnerability
28RIESGO
abrir
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RIESGO
abrir
GitHub PoC1
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies.
CVE-2026-55579CRITICAL17 jul 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
48RIESGO
abrir
GitHub PoC1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48205CRITICAL17 jul 2026
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RIESGO
abrir
GitHub PoC3
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2021-36260CRITICALbajo ataque17 jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
CVE-2026-15583HIGH17 jul 2026
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RIESGO
abrir
GitHub PoC54
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque17 jul 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46726HIGH16 jul 2026
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL16 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
GitHub PoC2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
CVE-2026-58457CRITICAL16 jul 2026
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RIESGO
abrir
GitHub PoC1
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
CVE-2026-14894CRITICAL16 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
GitHub PoC6
CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21333HIGHbajo ataque16 jul 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC2
syxlox/CVE-2026-50369
CVE-2026-50369HIGH16 jul 2026
Windows Remote Desktop Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a read to a destructive one (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46592HIGH16 jul 2026
Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
41RIESGO
abrir
anteriorpágina 39 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.