Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
21RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
13RIESGO
abrir
GitHub PoC
PoC for jenkins 2.63 CVE-2019-1003030
CVE-2019-1003030CRITICALbajo ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29114
CVE-2026-29114LOW11 jul 2026
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
8RIESGO
abrir
GitHub PoC6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
CVE-2026-43501CRITICAL11 jul 2026
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RIESGO
abrir
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 jul 2026
@vendure/core has a SQL Injection vulnerability
43RIESGO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHbajo ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
MW-HF/Drupal-CVE-2026-9082
CVE-2026-9082CRITICALbajo ataque11 jul 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALbajo ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL11 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALbajo ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALbajo ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC3
This is an exploit for CVE-2026-46215 (Linux Kernel Use After Free) Adapted for Linux 7.0 !!! by Antonius (ev1lut10n / sw0rdm4n)
CVE-2026-46215HIGH11 jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL11 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware10 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS 8.8)
CVE-2026-56423CRITICAL10 jul 2026
MISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpoints
28RIESGO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque10 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1
CVE-2026-54390CRITICAL10 jul 2026
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
28RIESGO
abrir
GitHub PoC
Dr-D25/CVE-2026-49049
CVE-2026-49049HIGH10 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
61RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
CVE-2026-40859HIGH10 jul 2026
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
21RIESGO
abrir
GitHub PoC2
A Proof of Concept (PoC) exploit for CVE-2026-46331
CVE-2026-46331HIGH10 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware10 jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM10 jul 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL10 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware10 jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RIESGO
abrir
anteriorpágina 46 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.