Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALbajo ataque27 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALbajo ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RIESGO
abrir
GitHub PoC4
GitLab Code injection
CVE-2026-19478CRITICAL27 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMbajo ataque27 ago 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RIESGO
abrir
GitHub PoC
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
CVE-2025-57819CRITICALbajo ataque27 ago 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC22
Metabase SQLi
CVE-2026-72898CRITICALbajo ataque27 ago 2026
Metabase SQL injection via password reset endpoint
100RIESGO
abrir
GitHub PoC
Gvln-S/CVE-2011-2523
CVE-2011-252327 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
CVE-2026-74936CRITICAL27 ago 2026
Use-after-free in the JavaScript: WebAssembly component
48RIESGO
abrir
GitHub PoC4
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
CVE-2026-18963CRITICAL27 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC1
sahmsec/CVE-2026-32475
CVE-2026-32475CRITICAL27 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
CVE-2026-77542CRITICAL27 ago 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63520HIGH26 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque26 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-76904CRITICAL26 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALbajo ataque26 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque26 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-36425MEDIUM26 ago 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-73570HIGHbajo ataque26 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
CVE-2026-72898CRITICALbajo ataque26 ago 2026
Metabase SQL injection via password reset endpoint
100RIESGO
abrir
GitHub PoC
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
CVE-2022-29303CRITICALbajo ataque26 ago 2026
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL26 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC2
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
GitHub PoC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
GitHub PoC
ksotaria1337/-CVE-2026-48907-
CVE-2026-48907CRITICALbajo ataque26 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC1
POC pre-auth RCE on Sharepoint chain
CVE-2026-63520HIGH26 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC
zenzue/CVE-2026-55040
CVE-2026-55040CRITICALbajo ataque26 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection
CVE-2026-56705CRITICAL26 ago 2026
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RIESGO
abrir
GitHub PoC
KongQBin/CVE-2016-5195
CVE-2016-5195HIGHbajo ataque26 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
anteriorpágina 13 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.