Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RIESGO
abrir ↗GitHub PoC
CVE-2026-31431-CopyFail---Minified-LPE-PoC
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗Exploit-DB
Cockpit 359 - RCE
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RIESGO
abrir ↗GitHub PoC★ 2
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via a kernel mode driver.
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1
41RIESGO
abrir ↗GitHub PoC★ 1
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autofstx.exe` from the offline WinRE image's `BootExecute` value and refreshes WinRE registration so BitLocker trust is reestablished.
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC
yangh-beep/CVE-2026-31431-C
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC★ 1
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RIESGO
abrir ↗GitHub PoC★ 24
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗GitHub PoC★ 2
Langflow Arbitrary Directory Deletion
Langflow: Path Traversal in Langflow Knowledge Bases API
48RIESGO
abrir ↗GitHub PoC★ 1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir ↗GitHub PoC
CVE-2026-0300 PAN-OS 12.1, 11.2, 11.1, 10.2
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
90RIESGO
abrir ↗GitHub PoC
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RIESGO
abrir ↗GitHub PoC★ 2
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
48RIESGO
abrir ↗GitHub PoC
CVE-2026-46680 exploit
containerd user ID handling bypass allows runAsNonRoot evasion
41RIESGO
abrir ↗GitHub PoC
Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)
Windows Snipping Tool Spoofing Vulnerability
33RIESGO
abrir ↗GitHub PoC★ 22
CVE-2026-45250: FreeBSD 14.4 setcred kernel buffer overflow (LPE)
Stack buffer overflow via setcred(2)
41RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-9082 | SA-CORE-2026-004
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir ↗Exploit-DB
FUXA 1.2.9 - RCE
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RIESGO
abrir ↗GitHub PoC
A Go implementation of dirtydecrypt (CVE-2026-31635)
rxrpc: fix oversized RESPONSE authenticator length check
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
CVE-2026-45829
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RIESGO
abrir ↗GitHub PoC
Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.
Ghost has a SQL Injection in its Content API
85RIESGO
abrir ↗GitHub PoC
gitgudKrish/cve-2025-29927-nextjs
Authorization Bypass in Next.js Middleware
85RIESGO
abrir ↗GitHub PoC
CVE-2024-4367–PDF.js-xss
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir ↗GitHub PoC
Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
41RIESGO
abrir ↗VulnCheck XDB
local
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.