Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC
CVE-2026-45247 - Draft
CVE-2026-45247CRITICALbajo ataque04 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir
GitHub PoC
Dhananjayasj/CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
CVE-2024-1698CRITICAL04 jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RIESGO
abrir
GitHub PoC2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815MEDIUM04 jun 2026
CVE-2026-6815
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALbajo ataque04 jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
GitHub PoC29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
CVE-2026-49975HIGH04 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir
GitHub PoC
CVE-2026-23631-Draft
CVE-2026-23631MEDIUM04 jun 2026
redis-server Lua use-after-free may allow remote code execution
33RIESGO
abrir
GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
CVE-2026-8732CRITICAL04 jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RIESGO
abrir
GitHub PoC13
Attack surface in the real-world environment of CVE-2026-41096
CVE-2026-41096CRITICAL04 jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
CVE-2026-5076CRITICAL04 jun 2026
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RIESGO
abrir
GitHub PoC
PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.
CVE-2026-23744CRITICAL03 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
local
CVE-2026-43500HIGH03 jun 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RIESGO
abrir
GitHub PoC2
Shcesama/cve-2023-4863-analysis
CVE-2023-4863HIGHbajo ataque03 jun 2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC6
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
CVE-2026-49975HIGH03 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque03 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
leehunkoo/hk_CVE-2025-32433
CVE-2025-32433CRITICALbajo ataque03 jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC13
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
CVE-2026-41089CRITICAL03 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-7465HIGH03 jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RIESGO
abrir
GitHub PoC
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305.
CVE-2026-10187CRITICAL03 jun 2026
Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow
48RIESGO
abrir
GitHub PoC1
Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)
CVE-2015-330603 jun 2026
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target
CVE-2021-44228CRITICALbajo ataqueransomware03 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
CVE-2026-42945CRITICAL03 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
CVE-2026-27145 - Draft
CVE-2026-27145MEDIUM03 jun 2026
Inefficient candidate hostname parsing in crypto/x509
33RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-0257HIGHbajo ataqueransomware03 jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
GitHub PoC1
Rocket.Chat OAuth2 NoSQL Injection
CVE-2026-29198CRITICAL03 jun 2026
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c
48RIESGO
abrir
GitHub PoC
Detection script for CIFSwitch - CVE-2026-46243
CVE-2026-46243HIGH03 jun 2026
smb: client: reject userspace cifs.spnego descriptions
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41089CRITICAL03 jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque03 jun 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL03 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
Galaxy-sc/CVE-2026-47423-dompurify-xss-detector
CVE-2026-47423HIGH03 jun 2026
DOMPurify XSS via `selectedcontent` re-clone
41RIESGO
abrir
GitHub PoC1
CVE-2025-48595 - Draft
CVE-2025-48595HIGHbajo ataque03 jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RIESGO
abrir
anteriorpágina 106 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.