Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
14.946 exploits
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RIESGO
abrir ↗GitHub PoC★ 1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RIESGO
abrir ↗GitHub PoC★ 5
CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RIESGO
abrir ↗GitHub PoC★ 1
Custom Content Types and Fields plugin for WordPress
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization
Microsoft Entra ID Remote Code Execution Vulnerability
48RIESGO
abrir ↗GitHub PoC
CVE-2026-69836 - Draft or TODO
Microsoft Entra ID Remote Code Execution Vulnerability
48RIESGO
abrir ↗GitHub PoC★ 1
Educational use only!
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RIESGO
abrir ↗GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RIESGO
abrir ↗GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir ↗GitHub PoC★ 1
Safely detect Citrix NetScaler CVE-2026-8452
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RIESGO
abrir ↗GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RIESGO
abrir ↗GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RIESGO
abrir ↗GitHub PoC
Analyze and reproduce CVE-2025-55182.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir ↗GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
Microsoft Copilot Information Disclosure Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 35
Exploit for KeyCloak CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
aarch64 race condition checker
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RIESGO
abrir ↗GitHub PoC★ 1
elkhaoudari/CVE-2018-7600-PoC
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 14
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
zavisco/CVE-2026-64849.yaml
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗GitHub PoC★ 1
halo cms plugin 1-request rce from a url, PoC + exploit chain
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RIESGO
abrir ↗GitHub PoC★ 1
Begitdj/cve-2019-2215-markw
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 531
A cPanel and WHM authentication bypassing tool
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 1
0xdeadroot/SCTPhantom-CVE-2026-64564
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.