Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.814exploits catalogados
32.125CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.248VulnCheck XDB 8150Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
71.760 exploits
GitHub PoC★ 2
CVE-2026-9082 | SA-CORE-2026-004
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC★ 2
Langflow Arbitrary Directory Deletion
Langflow: Path Traversal in Langflow Knowledge Bases API
48RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-9082
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC
A Go implementation of dirtydecrypt (CVE-2026-31635)
rxrpc: fix oversized RESPONSE authenticator length check
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC
CVE-2026-46680 exploit
containerd user ID handling bypass allows runAsNonRoot evasion
41RIESGO
abrir ↗GitHub PoC★ 1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
CVE-2026-0300 PAN-OS 12.1, 11.2, 11.1, 10.2
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
90RIESGO
abrir ↗GitHub PoC
CVE-2026-31431-CopyFail---Minified-LPE-PoC
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗Exploit-DB
FUXA 1.2.9 - RCE
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
48RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC★ 20
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RIESGO
abrir ↗GitHub PoC
「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC★ 1
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
48RIESGO
abrir ↗GitHub PoC
CVE-2026-45829
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RIESGO
abrir ↗GitHub PoC
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC
Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.
Ghost has a SQL Injection in its Content API
75RIESGO
abrir ↗GitHub PoC
gitgudKrish/cve-2025-29927-nextjs
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
MGTx2/CVE-2026-39107
A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails
33RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner for authorized testing.
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
48RIESGO
abrir ↗GitHub PoC
fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RIESGO
abrir ↗GitHub PoC
julianertle/CVE-2023-0386-CTF
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RIESGO
abrir ↗GitHub PoC
Exploit for DirtyDecrypt - CVE-2026-31635 Local Privilege Escalation
rxrpc: fix oversized RESPONSE authenticator length check
41RIESGO
abrir ↗GitHub PoC
A Go implementation of dirtyfrag (CVE-2026-43284 / CVE-2026-43500)
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.