Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
CVE-2026-18577 - Draft
CVE-2026-18577HIGHbajo ataque04 ago 2026
Incomplete patch leads to administrative account takeover
71RIESGO
abrir
GitHub PoC
python code use to check for user in ssh
CVE-2018-15473MEDIUM04 ago 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC5
WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).
CVE-2026-63030CRITICALbajo ataque04 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11108-Integer-Overflow-in-Memory-Allocator-kmalloc-Sim-
CVE-2026-11108HIGH04 ago 2026
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perf
41RIESGO
abrir
GitHub PoC
x-znn/CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque04 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-67340_exploit
CVE-2026-67340CRITICAL04 ago 2026
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
48RIESGO
abrir
GitHub PoC83
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution.
CVE-2026-47301HIGH03 ago 2026
Configuration Manager Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
DharmarajPS/pdfjs-cve-2024-4367-poc
CVE-2024-4367MEDIUM03 ago 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
CVE-2026-11105MEDIUM03 ago 2026
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RIESGO
abrir
GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
CVE-2026-17583 - Draft
CVE-2026-17583HIGH03 ago 2026
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11106-DNS-Zone-Transfer-AXFR-Information-Disclosure
CVE-2026-11106MEDIUM03 ago 2026
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-or
33RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11101-HTTP-Cache-Poisoning-via-Unkeyed-Query-Parameter
CVE-2026-11101MEDIUM03 ago 2026
Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-ori
33RIESGO
abrir
GitHub PoC1
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
CVE-2025-29927CRITICAL03 ago 2026
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
CVE-2026-11104MEDIUM03 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RIESGO
abrir
GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
CVE-2026-60137MEDIUMbajo ataque03 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC2
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary
CVE-2026-43499HIGH03 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CVE-2026-63223CRITICAL03 ago 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking
CVE-2026-11102HIGH03 ago 2026
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to e
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass
CVE-2026-11103HIGH03 ago 2026
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to
41RIESGO
abrir
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALbajo ataqueransomware03 ago 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
CVE-2026-48710MEDIUM03 ago 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RIESGO
abrir
GitHub PoC
CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for WordPress up to and including version 6.0.4.
CVE-2026-9848HIGH03 ago 2026
WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-8080-DKIM-Signature-Verification-Bypass-Header-Canonicalization-Flaw-
CVE-2026-8080MEDIUM03 ago 2026
MISP core - Stored XSS in MISP template (old engine) element attribute type
33RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-69083_exploit
CVE-2026-69083CRITICAL03 ago 2026
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RIESGO
abrir
GitHub PoC
sam00/POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability
CVE-2026-42826CRITICAL03 ago 2026
Azure DevOps Information Disclosure Vulnerability
48RIESGO
abrir
GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
CVE-2025-71338CRITICAL03 ago 2026
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-68771_exploit
CVE-2026-68771CRITICAL03 ago 2026
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
48RIESGO
abrir
GitHub PoC
sam00/POC-CVE-2026-54121-Certighost
CVE-2026-54121HIGH03 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.