Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
VulnCheck XDB
initial-access
CVE-2019-023212 jul 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20127CRITICALbajo ataque12 jul 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC2
Wordpress Plugin Planyo Online Reservation System <= 3.0 - Arbitrary File Read via SSRF
CVE-2026-3576HIGH12 jul 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-023212 jul 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)
CVE-2026-46331HIGH12 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque12 jul 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC
cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware12 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-43866 — Apache Camel camel-jms forged DefaultExchangeHolder bypass of the CVE-2026-40860 deserialization filter (Exchange-state injection)
CVE-2026-43866HIGH12 jul 2026
Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
41RIESGO
abrir
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALbajo ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir
GitHub PoC
Lim-ahmin/CVE-2021-43798
CVE-2021-43798HIGHbajo ataque11 jul 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC
A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x
CVE-2026-38526CRITICAL11 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC
WHS 4기 이희수. kr-vulhub 과제 제출물
CVE-2021-41773HIGHbajo ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
21RIESGO
abrir
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC1
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
CVE-2026-13768CRITICAL11 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
21RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
13RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29114
CVE-2026-29114LOW11 jul 2026
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
8RIESGO
abrir
GitHub PoC1
CVE-2026-46242
CVE-2026-46242HIGH11 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
21RIESGO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHbajo ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.
CVE-2012-1823CRITICALbajo ataque11 jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 jul 2026
@vendure/core has a SQL Injection vulnerability
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL11 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC3
This is an exploit for CVE-2026-46215 (Linux Kernel Use After Free) Adapted for Linux 7.0 !!! by Antonius (ev1lut10n / sw0rdm4n)
CVE-2026-46215HIGH11 jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALbajo ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALbajo ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL11 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
anteriorpágina 45 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.