Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC2
Proof-of-concept for CVE-2026-43284 — 4-byte XFRM/ESP page-cache write primitive to patch a setuid binary (x86_64, user namespaces). Includes kernel preflight + SUID scan.
CVE-2026-43284HIGH26 may 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin
CVE-2026-5718HIGH26 may 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RIESGO
abrir
GitHub PoC1
Cisco Catalyst SD-WAN Peering Authentication Bypass
CVE-2026-20182CRITICALbajo ataque26 may 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
xxconi/CVE-2026-6271
CVE-2026-6271CRITICAL26 may 2026
Career Section <= 1.7 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALbajo ataque26 may 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC
xl337x/CVE-2023-31902
CVE-2023-31902CRITICAL26 may 2026
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
63RIESGO
abrir
GitHub PoC2
CVE-2026-48095
CVE-2026-48095HIGH26 may 2026
GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
41RIESGO
abrir
GitHub PoC
CVE-2026-6741 is a CVSS 8.8 (High) Authenticated (Agent+) Privilege Escalation vulnerability in the LatePoint – Calendar Booking Plugin
CVE-2026-6741HIGH26 may 2026
LatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
41RIESGO
abrir
GitHub PoC
CVE-2026-5426
CVE-2026-5426CRITICAL26 may 2026
KnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value
48RIESGO
abrir
VulnCheck XDB
local
CVE-2026-43284HIGH26 may 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
xxconi/CVE-2026-2942
CVE-2026-2942CRITICAL26 may 2026
ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20182CRITICALbajo ataque26 may 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin
CVE-2026-3296CRITICAL26 may 2026
Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
63RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware26 may 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC1
Working exploit for ssrf issue reported in CVE-2026–45401
CVE-2026-45401HIGH26 may 2026
Open WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints
41RIESGO
abrir
GitHub PoC
CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)
CVE-2026-5229CRITICAL26 may 2026
Receive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth Callback
48RIESGO
abrir
GitHub PoC
Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol
CVE-2025-55182CRITICALbajo ataqueransomware26 may 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC11
ambionics/cve-2026-9082-drupal-postgresql-rce
CVE-2026-9082CRITICALbajo ataque26 may 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC
CVE-2026-5364 is a CVSS 8.1 (High) Unauthenticated Arbitrary File Upload vulnerability in the Drag and Drop File Upload for Contact Form 7
CVE-2026-5364HIGH26 may 2026
Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass
41RIESGO
abrir
GitHub PoC
CVE-2021-43798 MiNi Exploitation Framework
CVE-2021-43798HIGHbajo ataque26 may 2026
Grafana path traversal
100RIESGO
abrir
Exploit-DB
cPanel - CRLF Injection
CVE-2026-41940CRITICALbajo ataqueransomwarewebappsphp26 may 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Exploit-DB
Grav CMS 2.0.0-beta.2 - Remote Code Execution
CVE-2026-42607CRITICALwebappsphp26 may 2026
Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
48RIESGO
abrir
GitHub PoC6
DbGate Unauthenticated Remote Code Execution
CVE-2026-47668CRITICAL26 may 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RIESGO
abrir
GitHub PoC
xxconi/CVE-2026-46275
CVE-2026-46275HIGH26 may 2026
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
41RIESGO
abrir
GitHub PoC
A proof of concept for CVE 2024 23113 inspired by WatchTowr's article.
CVE-2024-23113CRITICALbajo ataque25 may 2026
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RIESGO
abrir
GitHub PoC
renewablehacking/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALbajo ataqueransomware25 may 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RIESGO
abrir
GitHub PoC
notthemystery/CVE-2026-20700-POC-that-ll-never-work
CVE-2026-20700HIGHbajo ataque25 may 2026
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3,
71RIESGO
abrir
GitHub PoC
Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in FiberHome HG6145F1 GPON ONT devices.
CVE-2025-63353CRITICAL25 may 2026
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL25 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL25 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
anteriorpágina 116 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.