Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC
Technical writeup and penetration testing report for CVE-2010-2075, demonstrating UnrealIRCd backdoor exploitation and remediation.
CVE-2010-207505 jun 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC21
TheCyberGeek/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL05 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL05 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
GitHub PoC
seguridadentrerios/CVE-2026-33829
CVE-2026-33829MEDIUM05 jun 2026
Windows Snipping Tool Spoofing Vulnerability
33RIESGO
abrir
Exploit-DB
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
CVE-2026-3180HIGHwebappsmultiple05 jun 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RIESGO
abrir
GitHub PoC1
Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection
CVE-2026-11349HIGH05 jun 2026
Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more
41RIESGO
abrir
GitHub PoC
yurahshell/CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware05 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)
CVE-2026-45585MEDIUM04 jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31635HIGH04 jun 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RIESGO
abrir
GitHub PoC1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
CVE-2026-42945CRITICAL04 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
CVE-2013-611704 jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CVE-2026-34234CRITICAL04 jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RIESGO
abrir
GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
CVE-2026-35904CRITICAL04 jun 2026
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RIESGO
abrir
GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
CVE-2024-46987HIGH04 jun 2026
Arbitrary path traversal in Camaleon CMS
61RIESGO
abrir
GitHub PoC13
Attack surface in the real-world environment of CVE-2026-41096
CVE-2026-41096CRITICAL04 jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC1
horrister/log4shell-cve-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware04 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
CVE-2026-8732CRITICAL04 jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RIESGO
abrir
GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4883CRITICAL04 jun 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RIESGO
abrir
GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
CVE-2026-50142HIGH04 jun 2026
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware04 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2026-23744
CVE-2026-23744CRITICAL04 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
CVE-2026-49975HIGH04 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2024-1698CRITICAL04 jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC
Dhananjayasj/CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
CVE-2024-1698CRITICAL04 jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-34234CRITICAL04 jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALbajo ataque04 jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
GitHub PoC1
horrister/solarwinds-sunburst-cve-2020-10148
CVE-2020-10148CRITICALbajo ataque04 jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2013-611704 jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
GitHub PoC
0-Click RCE Android Adb TLS Wireless Debugging
CVE-2026-0073HIGH04 jun 2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
anteriorpágina 105 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.