Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
VulnCheck XDB
initial-access
CVE-2026-8054CRITICAL09 jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RIESGO
abrir
GitHub PoC
Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)
CVE-2026-48598LOW09 jun 2026
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
28RIESGO
abrir
GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
CVE-2026-46394HIGH09 jun 2026
HAX CMS Vulnerable to Command Injection using Git.php
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque09 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-11262HIGH09 jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-28318
CVE-2026-28318HIGHbajo ataque09 jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RIESGO
abrir
GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
CVE-2026-47429CRITICAL09 jun 2026
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RIESGO
abrir
GitHub PoC1
Proof-of-concept demonstrating cross-user X11 session compromise in Pardus LightDM Greeter caused by the unsafe `xhost +local:` configuration, including unauthorized shell access, display access, screen capture, window enumeration, and XTEST input injection.
CVE-2026-79617HIGH09 jun 2026
Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
41RIESGO
abrir
GitHub PoC
CVE-2026-42271 - Draft
CVE-2026-42271HIGHbajo ataque09 jun 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RIESGO
abrir
GitHub PoC1
CVE-2026-48907: Unauthenticated RCE in JCE (Proof Of Concept)
CVE-2026-48907CRITICALbajo ataque09 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
CVE-2026-45247CRITICALbajo ataque09 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-48595
CVE-2026-48595HIGH09 jun 2026
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RIESGO
abrir
GitHub PoC
CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)
CVE-2021-44228CRITICALbajo ataqueransomware09 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-35616
CVE-2026-35616CRITICALbajo ataque09 jun 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-42945
CVE-2026-42945CRITICAL09 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
CVE-2026-3180HIGH08 jun 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RIESGO
abrir
GitHub PoC1
Mitigation scripts for CVE-2026-50751
CVE-2026-50751CRITICALbajo ataqueransomware08 jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-7465-Lab
CVE-2026-7465HIGH08 jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RIESGO
abrir
GitHub PoC2
CVE-2026-11499
CVE-2026-11499CRITICAL08 jun 2026
Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC1
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque08 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque08 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
CVE-2026-43512CRITICAL08 jun 2026
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1676308 jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
CVE-2026-45585MEDIUM08 jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALbajo ataque08 jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
willygailo/WG-CVE-2026-1555-Linux
CVE-2026-1555CRITICAL08 jun 2026
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque08 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-21716CRITICAL08 jun 2026
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
CVE-2026-49975HIGH08 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir
anteriorpágina 101 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.