Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
77.866 exploits
GitHub PoC
Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable systems with false-positive detection.
CVE-2026-24061CRITICALbajo ataque10 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
sudoand3rs0n/CVE-2025-5548
CVE-2025-5548MEDIUM10 jul 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM10 jul 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
GitHub PoC
CVE-2026-28992 IOHIDFamily FastPathUserClient race condition PoC — security research
CVE-2026-28992MEDIUM10 jul 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque10 jul 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC1
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)
CVE-2026-40858HIGH10 jul 2026
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
41RIESGO
abrir
GitHub PoC1
inforcqb/CVE-2026-43499-pja110
CVE-2026-43499HIGH10 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-51833 Advisory
CVE-2026-51833HIGH10 jul 2026
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RIESGO
abrir
GitHub PoC
caspy123/CVE-2026-43499
CVE-2026-43499HIGH10 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40473: Apache Camel camel-mina MinaConverter.toObjectInput unsafe deserialization (RCE over TCP/UDP)
CVE-2026-40473HIGH09 jul 2026
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
41RIESGO
abrir
GitHub PoC1
Offical PoC for this cve
CVE-2026-56876HIGH09 jul 2026
extract-zip unvalidated symlink path traversal
21RIESGO
abrir
GitHub PoC
Public disclosure for CVE-2026-52100 (CSRF) & CVE-2026-52101 (SSRF) in linx-server. MITRE assigned the CVEs; this repo provides a public reference and helps affected users understand the risk.
CVE-2026-52100HIGH09 jul 2026
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e
21RIESGO
abrir
GitHub PoC
Librebooking Admin RCE PoC CVE-2026-61343
CVE-2026-61343HIGH09 jul 2026
LibreBooking path traversal
21RIESGO
abrir
GitHub PoC
PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)
CVE-2026-49230MEDIUM09 jul 2026
Apache APISIX: Authentication bypass in jwe-decrypt
13RIESGO
abrir
GitHub PoC1
0x00phantom-hat/CVE-2026-12400-Exploit
CVE-2026-12400MEDIUM09 jul 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
13RIESGO
abrir
GitHub PoC1
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
CVE-2026-53359漏洞补丁
CVE-2026-53359HIGH09 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC
CVE-2026-50746... - Draft
CVE-2026-50746CRITICAL09 jul 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
28RIESGO
abrir
GitHub PoC1
CVE-2026-53571 `server.fs.deny` bypass on Windows alternate paths PoC.
CVE-2026-53571HIGH09 jul 2026
Vite: `server.fs.deny` bypass on Windows alternate paths
21RIESGO
abrir
GitHub PoC
johnwickakash12/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware09 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE
CVE-2026-4257CRITICAL09 jul 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RIESGO
abrir
GitHub PoC1
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50181HIGH09 jul 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
21RIESGO
abrir
GitHub PoC
endusdksla/xwiki-cve-2025-24893
CVE-2025-24893CRITICALbajo ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
Whitehat School 4기 CVE-2021-4034 분석 및 POC 작성
CVE-2021-4034HIGHbajo ataqueransomware09 jul 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
cazzysoci/cve-2026-48908
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir
GitHub PoC1
lieehrdiansyah12/CVE-2026-43503
CVE-2026-43503HIGH09 jul 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48908 in Joomla SP Page Builder, covering unauthorized icon upload, PHP file write, code execution as www-data, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1571509 jul 2026
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a ma
60RIESGO
abrir
anteriorpágina 47 / 2596siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.