Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC
Spring4Shell (CVE-2022-22965) 漏洞環境搭建與 CTF 題目
CVE-2022-22965CRITICALbajo ataque27 may 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
PrintNightmare Report
CVE-2021-34527HIGHbajo ataqueransomware27 may 2026
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2026-45659
CVE-2026-45659HIGHbajo ataqueransomware27 may 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RIESGO
abrir
GitHub PoC
Lab 3: Supervisord XML-RPC Remote Code Execution (CVE-2017-11610) - Writeup and Exploit
CVE-2017-1161027 may 2026
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
GitHub PoC1
mein-0/cve-2026-0828
CVE-2026-0828HIGH27 may 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1161027 may 2026
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHbajo ataque27 may 2026
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque27 may 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710
CVE-2026-48710MEDIUMbajo ataque27 may 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RIESGO
abrir
GitHub PoC
SSRF Discovered in Mercator
CVE-2026-49345MEDIUM27 may 2026
Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
13RIESGO
abrir
GitHub PoC
hadhub/CVE-2026-49344-Mercator-JSON-DSL
CVE-2026-49344HIGH27 may 2026
Mercator has a Personal Identifiable Information Leak from Query Executor feature
21RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware27 may 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed multiple times against the same target without waiting for cache expiration.
CVE-2019-6340HIGHbajo ataque27 may 2026
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2021-3560 — Polkit privilege escalation exploit via accounts-daemon D-Bus race condition
CVE-2021-3560HIGHbajo ataque27 may 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque27 may 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque27 may 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
this is a study about CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
CVE-2021-3156HIGHbajo ataque27 may 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Exploit-DB
Linux Kernel - Local Privilege Escalation
CVE-2026-43500HIGHlocallinux27 may 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RIESGO
abrir
Exploit-DB
scramble - Remote Code Execution
CVE-2026-44262CRITICALwebappsphp27 may 2026
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RIESGO
abrir
GitHub PoC
lwd3c/CVE-2026-47342
CVE-2026-47342HIGH27 may 2026
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
21RIESGO
abrir
Exploit-DB
Linux Kernel - Local Privilege Escalation
CVE-2026-43284HIGHlocallinux27 may 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC2
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
CVE-2026-41940CRITICALbajo ataqueransomware27 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
Realtek rtl819x - Local Privilege
CVE-2026-36355HIGHlocallinux27 may 2026
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-9082CRITICALbajo ataque27 may 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC
CVE-2026-27771
CVE-2026-27771HIGH27 may 2026
Gitea Composer package source links use insufficient permission checks
56RIESGO
abrir
Exploit-DB
MeiG Smart FORGE_SLT711 - OS Command Injection
CVE-2026-36356CRITICALhardwarelinux27 may 2026
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
53RIESGO
abrir
GitHub PoC
CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin
CVE-2026-3296CRITICAL26 may 2026
Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
63RIESGO
abrir
GitHub PoC1
Cisco Catalyst SD-WAN Peering Authentication Bypass
CVE-2026-20182CRITICALbajo ataque26 may 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
xxconi/CVE-2026-46275
CVE-2026-46275HIGH26 may 2026
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware26 may 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
anteriorpágina 115 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.