Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.697exploits catalogados
36.715CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8920Nuclei 4373Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.697 exploits
GitHub PoC
CVE-2026-67276 MikroTik RouterOS SSH Authentication Bypass Exploit
SSH user impersonation possible in Mikrotik RouterOS
48RIESGO
abrir ↗GitHub PoC
CVE-2026-86218 - Draft or TODO - N-central is vulnerable to a pre-auth remote code execution
pre-authentication remote code execution
78RIESGO
abrir ↗GitHub PoC
Eliot-code/CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗VulnCheck XDB
initial-access
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-82329 — JFrog Artifactory Auth Bypass
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir ↗VulnCheck XDB
client-side
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir ↗VulnCheck XDB
initial-access
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir ↗GitHub PoC
CVE-2026-81780 — Hash Form RCE
WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir ↗VulnCheck XDB
info-leak
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir ↗VulnCheck XDB
initial-access
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RIESGO
abrir ↗GitHub PoC★ 30
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗VulnCheck XDB
initial-access
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC
0xCyp1337/CVE-2026-82222-MassExploit
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir ↗VulnCheck XDB
info-leak
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir ↗página 1 / 2657siguiente →
Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.