Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DB
WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI
CVE-2026-4257CRITICALwebappsmultiple14 may 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319214 may 2026
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
GitHub PoC5
CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept
CVE-2026-8181CRITICAL14 may 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
VulnCheck XDB
local
CVE-2026-46300HIGH14 may 2026
net: skbuff: preserve shared-frag marker during coalescing
56RIESGO
abrir
GitHub PoC1
Sentebale/CVE-2026-46300
CVE-2026-46300HIGH14 may 2026
net: skbuff: preserve shared-frag marker during coalescing
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL14 may 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC
A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment
CVE-2023-23752MEDIUMbajo ataque14 may 2026
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC
Test repo: simulates CVE-2025-30066 style compromised GitHub Action (for security research/testing chainradar)
CVE-2025-30066HIGHbajo ataque14 may 2026
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
Metasploit500
Fragnesia LPE (CVE-2026-46300)
CVE-2026-46300HIGH14 may 2026
net: skbuff: preserve shared-frag marker during coalescing
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
mbanyamer/CVE-2026-22553-InSAT-MasterSCADA-BUK-TS-MMadmServ
CVE-2026-22553CRITICAL14 may 2026
InSAT MasterSCADA BUK-TS OS Command Injection
48RIESGO
abrir
GitHub PoC2
CVE-2005-0575 - KNet Web Server 1.04b Remote Buffer Overflow SEH Exploit for x86 Windows XP SP3, this exploit needs some adjustment ! edit the code before run ! Developed by Antonius - made in the past, I forgot when I made it
CVE-2005-057514 may 2026
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RIESGO
abrir
GitHub PoC2
nanwinata/nginxrift-CVE-2026-42945
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC21
NGINX Rift 漏洞分析与复现
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC54
exploit for CVE-2026-42945
CVE-2026-42945CRITICAL14 may 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC1
Proof of concept exploit for CVE-2026-46391
CVE-2026-46391HIGH14 may 2026
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
41RIESGO
abrir
GitHub PoC
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
CVE-2026-6145MEDIUM14 may 2026
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
33RIESGO
abrir
GitHub PoC
OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)
CVE-2026-44578HIGH13 may 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RIESGO
abrir
GitHub PoC2
Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacker commits. Python, Bash, PowerShell.
CVE-2026-45321CRITICALbajo ataqueransomware13 may 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RIESGO
abrir
GitHub PoC
Checker and fixer for all 13 vulnerabilities in the Next.js May 2026 security release (CVE-2026-23870)
CVE-2026-23870HIGH13 may 2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo
41RIESGO
abrir
GitHub PoC
this little script blocks the new splice-ram-privlilleg ecalation fastly befor the contributers do it ( CVE-2026-31431) (CopyFail fix)
CVE-2026-31431HIGHbajo ataque13 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
copy-fail-CVE-2026-31431
CVE-2026-31431HIGHbajo ataque13 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
Reproduced the fileless LPE CVE‑2026‑31431 (“Copy Fail”) on Kali Linux, then built auditd, Sigma & YARA detections to catch this stealthy kernel exploit that leaves no disk footprint.
CVE-2026-31431HIGHbajo ataque13 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC
pixelotes/lab-cve-2023-4863
CVE-2023-4863HIGHbajo ataque13 may 2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RIESGO
abrir
GitHub PoC3
A Bash implementation of copyfail (CVE-2026-31431)
CVE-2026-31431HIGHbajo ataque13 may 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
anteriorpágina 131 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.