Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.302exploits catalogados
36.463CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque24 ago 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque24 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-76904CRITICAL24 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
GitHub PoC
Patch: Authentication bypass (VMware vCenter)
CVE-2026-11553HIGH24 ago 2026
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque24 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC
Patch: OGNL injection (Apache Struts)
CVE-2026-10520CRITICAL24 ago 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
h00die/POC-CVE-2026-19679
CVE-2026-19679HIGH24 ago 2026
Improper Input Validation
41RIESGO
abrir
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 ago 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RIESGO
abrir
GitHub PoC
Patch: Remote code execution in SPL parsing (Splunk Enterprise)
CVE-2026-28001CRITICAL24 ago 2026
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
48RIESGO
abrir
GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-20333CRITICALbajo ataque24 ago 2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu
100RIESGO
abrir
GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
CVE-2026-66916MEDIUM23 ago 2026
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RIESGO
abrir
GitHub PoC
Professional PHPMyAdmin 5.0.0 SQL Injection (CVE-2020-5504) exploitation framework with automated database enumeration, table extraction, and data dumping capabilities. Features blind injection, proxy support, JSON output, and comprehensive error handling for authorized penetration testing and security research. Author: Sudeepa Wanigarathna
CVE-2020-550423 ago 2026
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RIESGO
abrir
GitHub PoC
Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.
CVE-2011-252323 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary R/W -> RCE
CVE-2026-15718MEDIUM23 ago 2026
Invalid pointer in the JavaScript: WebAssembly component
33RIESGO
abrir
GitHub PoC
h00die/POC-CVE-2026-19681
CVE-2026-19681CRITICAL23 ago 2026
Command Injection
63RIESGO
abrir
GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
CVE-2009-065823 ago 2026
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RIESGO
abrir
GitHub PoC
chessalekin/cve-2026-9198_exploit
CVE-2026-9198CRITICALbajo ataque23 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation
CVE-2026-23744CRITICAL23 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
CVE-2026-66917HIGH23 ago 2026
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RIESGO
abrir
GitHub PoC1
Legendile7/CVE-2026-78122-POC
CVE-2026-78122HIGH23 ago 2026
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RIESGO
abrir
GitHub PoC4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
CVE-2026-10053HIGH23 ago 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RIESGO
abrir
GitHub PoC
ts zeroday exp made by nullsec white team
CVE-2026-41940CRITICALbajo ataqueransomware22 ago 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
CVE-2026-47630 — NVIDIA Triton Inference Server: arbitrary dlopen via TRITON_BATCH_STRATEGY_PATH
CVE-2026-47630MEDIUM22 ago 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
33RIESGO
abrir
GitHub PoC
Gitlab-CVE-2026-19478
CVE-2026-19478CRITICAL22 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC164
POC pre-auth RCE on Exchange
CVE-2026-62911HIGH22 ago 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2004-268722 ago 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir
GitHub PoC
Detection & precondition-verification tool for CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter)
CVE-2026-58231CRITICAL22 ago 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RIESGO
abrir
GitHub PoC
Copy Fail CVE-2016-5195
CVE-2016-5195HIGHbajo ataque22 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.