Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
14.316 exploits
GitHub PoC
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-70559
Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
41RIESGO
abrir ↗GitHub PoC
Hunt-Benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
41RIESGO
abrir ↗GitHub PoC★ 7
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-0163 Exploit
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RIESGO
abrir ↗GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
35RIESGO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RIESGO
abrir ↗GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
Notepad++: session.xml backupFilePath starts_with Bypass
33RIESGO
abrir ↗GitHub PoC★ 2
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
SQL injection in ext-pgsql via E'...' backslash breakout
41RIESGO
abrir ↗GitHub PoC★ 1
woshidashabi1126/CVE-2026-70553-PoC
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RIESGO
abrir ↗GitHub PoC★ 1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir ↗GitHub PoC★ 5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RIESGO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RIESGO
abrir ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
Trezor Safe improper security check in on-device display
13RIESGO
abrir ↗GitHub PoC
tfawnies/CVE-2026-64633
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RIESGO
abrir ↗GitHub PoC★ 4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-69098_exploit
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RIESGO
abrir ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RIESGO
abrir ↗GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RIESGO
abrir ↗GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
Apache Tomcat: HTTP/2 request headers not validated
48RIESGO
abrir ↗GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
Unauthenticated administrative account takeover
71RIESGO
abrir ↗GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RIESGO
abrir ↗GitHub PoC★ 54
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
78RIESGO
abrir ↗GitHub PoC
hasan8babiker/CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir ↗GitHub PoC
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RIESGO
abrir ↗GitHub PoC
ICS-Park Smart Park Management System v2.0
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RIESGO
abrir ↗GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
Stapled OCSP response accepted without binding to the checked certificate
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.