Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
GitHub PoC
Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
28RIESGO
abrir ↗GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
HAX CMS Vulnerable to Command Injection using Git.php
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗VulnCheck XDB
client-side
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RIESGO
abrir ↗GitHub PoC
jenniferreire26/CVE-2026-28318
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RIESGO
abrir ↗GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RIESGO
abrir ↗GitHub PoC★ 1
Proof-of-concept demonstrating cross-user X11 session compromise in Pardus LightDM Greeter caused by the unsafe `xhost +local:` configuration, including unauthorized shell access, display access, screen capture, window enumeration, and XTEST input injection.
Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
41RIESGO
abrir ↗GitHub PoC
CVE-2026-42271 - Draft
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-48907: Unauthenticated RCE in JCE (Proof Of Concept)
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir ↗GitHub PoC
jenniferreire26/CVE-2026-48595
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RIESGO
abrir ↗GitHub PoC
CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
jenniferreire26/CVE-2026-35616
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir ↗GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RIESGO
abrir ↗GitHub PoC★ 1
Mitigation scripts for CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir ↗GitHub PoC
rootdirective-sec/CVE-2026-7465-Lab
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RIESGO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC★ 1
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RIESGO
abrir ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC
willygailo/WG-CVE-2026-1555-Linux
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir ↗VulnCheck XDB
initial-access
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC★ 2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.