Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
local
CVE-2026-36425MEDIUM26 ago 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir
GitHub PoC
zenzue/CVE-2026-55040
CVE-2026-55040CRITICALbajo ataque26 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque26 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALbajo ataque26 ago 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-76904CRITICAL26 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque26 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63520HIGH26 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
GitHub PoC
KongQBin/CVE-2016-5195
CVE-2016-5195HIGHbajo ataque26 ago 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
CVE-2026-12684MEDIUM26 ago 2026
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RIESGO
abrir
GitHub PoC
ksotaria1337/-CVE-2026-48907-
CVE-2026-48907CRITICALbajo ataque26 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
Poc CVE-2026-18080
CVE-2026-18080CRITICAL26 ago 2026
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RIESGO
abrir
GitHub PoC1
POC pre-auth RCE on Sharepoint chain
CVE-2026-63520HIGH26 ago 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
GitHub PoC2
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 ago 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir
GitHub PoC
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
CVE-2026-60004CRITICALbajo ataque25 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2026-18963 by BlackHatExploitation
CVE-2026-18963CRITICAL25 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
CVE-2026-16348HIGH25 ago 2026
Command Injection Vulnerability in VPN connection of Archer BE800
41RIESGO
abrir
GitHub PoC1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
CVE-2026-12295CRITICAL25 ago 2026
Sandbox escape in the DOM: Navigation component
48RIESGO
abrir
GitHub PoC35
CVE 1-day in http.sys
CVE-2026-62735HIGH25 ago 2026
Windows HTTP.sys Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-60004CRITICALbajo ataque25 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.
CVE-2018-1676325 ago 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
CVE-2026-68820HIGHbajo ataque25 ago 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
CVE-2026-58073CRITICAL25 ago 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RIESGO
abrir
GitHub PoC1
Use cve-2026-36425 killer edr,360 can killer
CVE-2026-36425MEDIUM25 ago 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-2890625 ago 2026
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL25 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-77806CRITICAL25 ago 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RIESGO
abrir
GitHub PoC1
PoC, Dockerfile playground and root cause from patch diff analysis.
CVE-2026-18963CRITICAL25 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
anteriorpágina 14 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.