Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC
Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)
CVE-2026-41091HIGHbajo ataque22 may 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab, empirical address discovery, OOB-verified offset sweep. Original disclosure by depthfirst.
CVE-2026-42945CRITICAL22 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-894222 may 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
GitHub PoC
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass
CVE-2026-8181CRITICAL22 may 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any incorrect password in a Basic Authentication header. Attackers could abuse this flaw to create a new administrator account without prior authentication.
CVE-2026-8181CRITICAL22 may 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC
NullByte8080/CVE-2026-36227
CVE-2026-36227MEDIUM22 may 2026
Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e
33RIESGO
abrir
GitHub PoC
NullByte8080/CVE-2026-36228
CVE-2026-36228HIGH22 may 2026
Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu
41RIESGO
abrir
GitHub PoC
jaf0rk/CVE-2026-5281
CVE-2026-5281HIGHbajo ataque22 may 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RIESGO
abrir
GitHub PoC
Critical WIC bug (9.8): uninitialized JPEG encode pointers in WindowsCodecs.dll — triggers on 12/16-bit re-encode, not casual preview.
CVE-2025-50165CRITICAL22 may 2026
Windows Graphics Component Remote Code Execution Vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL22 may 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
GitHub PoC
Pumila03/CVE-2026-6009
CVE-2026-6009HIGH22 may 2026
Jaspersoft Library Deserialisation Vulnerability
41RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL22 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC2
Safely detect whether a PAN-OS target is vulnerable to CVE-2026-0265.
CVE-2026-0265HIGH22 may 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALbajo ataque22 may 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque22 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
CVE-2026-42208 - LiteLLM SQL Injection vulnerability scanner for BerriAI LiteLLM proxy instances
CVE-2026-42208CRITICALbajo ataque22 may 2026
LiteLLM: SQL injection in Proxy API key verification
100RIESGO
abrir
GitHub PoC
A Go implementation of PinTheft (CVE-2026-43494)
CVE-2026-43494HIGH22 may 2026
net/rds: reset op_nents when zerocopy page pin fails
41RIESGO
abrir
GitHub PoC
CVE-2026-20223
CVE-2026-20223CRITICAL22 may 2026
Cisco Secure Workload Unauthorized API Access Vulnerability
48RIESGO
abrir
GitHub PoC
Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model Runner MLX / SGLANG / VLLM inference backend.
CVE-2026-5817HIGH22 may 2026
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
41RIESGO
abrir
GitHub PoC3
eprocess offset puller for relevant member offsets and function addresses for cve-2026-40369
CVE-2026-40369HIGH22 may 2026
Windows Kernel Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC2
Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)
CVE-2026-9082CRITICALbajo ataque22 may 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC2
CVE-2026-43494
CVE-2026-43494HIGH22 may 2026
net/rds: reset op_nents when zerocopy page pin fails
41RIESGO
abrir
GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
CVE-2026-31431HIGHbajo ataque22 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
CVE-2026-34926
CVE-2026-34926MEDIUMbajo ataque22 may 2026
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t
68RIESGO
abrir
GitHub PoC
NullByte8080/CVE-2026-36226
CVE-2026-36226MEDIUM22 may 2026
Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit
33RIESGO
abrir
GitHub PoC
BastianXploited/CVE-2026-8181
CVE-2026-8181CRITICAL22 may 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque22 may 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
CVE-2024-6387 POC (Currently being edited)
CVE-2024-6387HIGH22 may 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943
CVE-2019-894222 may 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
GitHub PoC2
A safe read-only Linux check for CVE-2026-31431 / Copy Fail without running exploit code.
CVE-2026-31431HIGHbajo ataque22 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
anteriorpágina 120 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.