Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
VulnCheck XDB
local
CVE-2023-2640HIGH10 jun 2026
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RIESGO
abrir
GitHub PoC
CVE-2026-48962 - IO::Compress - Code Execution
CVE-2026-48962HIGH10 jun 2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque10 jun 2026
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
OSCP like CVE-2025-24893 exploit for Linux XWiki
CVE-2025-24893CRITICALbajo ataque10 jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC3
PoC de CVE-2026-11645: lectura/escritura fuera de limites en Chrome V8 (CVSS 8.8).
CVE-2026-11645HIGHbajo ataque10 jun 2026
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0257HIGHbajo ataqueransomware10 jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware10 jun 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL10 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
CVE-2026-47429CRITICAL09 jun 2026
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-45247CRITICALbajo ataque09 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir
GitHub PoC
CVE-2026-45067 - Draft
CVE-2026-45067MEDIUM09 jun 2026
Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
33RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-0257
CVE-2026-0257HIGHbajo ataqueransomware09 jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-28318
CVE-2026-28318HIGHbajo ataque09 jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2024-21182
CVE-2024-21182HIGHbajo ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-41089
CVE-2026-41089CRITICAL09 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-48595
CVE-2026-48595HIGH09 jun 2026
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL09 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-35616
CVE-2026-35616CRITICALbajo ataque09 jun 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir
GitHub PoC
CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)
CVE-2021-44228CRITICALbajo ataqueransomware09 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
CVE-2026-45247CRITICALbajo ataque09 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir
GitHub PoC
CVE-2024-52011 - Draft
CVE-2024-52011HIGH09 jun 2026
launch-editor vulnerable to command injection via the crafted request on Windows
41RIESGO
abrir
GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
CVE-2026-46394HIGH09 jun 2026
HAX CMS Vulnerable to Command Injection using Git.php
41RIESGO
abrir
GitHub PoC
PoC and writeup for CVE-2026-46395: unauthenticated private key disclosure via broken HMAC in HAXcms Node.js (CWE-321/CWE-200). Authorized security research only.
CVE-2026-46395CRITICAL09 jun 2026
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
48RIESGO
abrir
GitHub PoC
CVE-2026-42271 - Draft
CVE-2026-42271HIGHbajo ataque09 jun 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RIESGO
abrir
GitHub PoC
fevar54/CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE
CVE-2024-21182HIGHbajo ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RIESGO
abrir
GitHub PoC1
Insert PHP Plugin PHP Code Injection
CVE-2017-20251CRITICAL09 jun 2026
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
48RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2025-11262-Lab
CVE-2025-11262HIGH09 jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RIESGO
abrir
GitHub PoC1
Proof-of-concept demonstrating cross-user X11 session compromise in Pardus LightDM Greeter caused by the unsafe `xhost +local:` configuration, including unauthorized shell access, display access, screen capture, window enumeration, and XTEST input injection.
CVE-2026-79617HIGH09 jun 2026
Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
41RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-45659
CVE-2026-45659HIGHbajo ataqueransomware09 jun 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de hardening
CVE-2024-42327CRITICAL09 jun 2026
SQL injection in user.get API
70RIESGO
abrir
anteriorpágina 100 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.