Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
VulnCheck XDB
local
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir ↗GitHub PoC
zenzue/CVE-2026-55040
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
info-leak
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir ↗VulnCheck XDB
local
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
initial-access
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir ↗VulnCheck XDB
initial-access
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir ↗GitHub PoC
KongQBin/CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗GitHub PoC
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RIESGO
abrir ↗GitHub PoC
ksotaria1337/-CVE-2026-48907-
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗GitHub PoC
Poc CVE-2026-18080
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RIESGO
abrir ↗GitHub PoC★ 1
POC pre-auth RCE on Sharepoint chain
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RIESGO
abrir ↗GitHub PoC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-19632 - TranslatePress One-Day PoC
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RIESGO
abrir ↗GitHub PoC
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir ↗GitHub PoC
Exploit for CVE-2026-18963 by BlackHatExploitation
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Command Injection Vulnerability in VPN connection of Archer BE800
41RIESGO
abrir ↗GitHub PoC★ 1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
Sandbox escape in the DOM: Navigation component
48RIESGO
abrir ↗GitHub PoC★ 35
CVE 1-day in http.sys
Windows HTTP.sys Elevation of Privilege Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir ↗GitHub PoC
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RIESGO
abrir ↗GitHub PoC★ 1
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RIESGO
abrir ↗GitHub PoC★ 1
Use cve-2026-36425 killer edr,360 can killer
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir ↗VulnCheck XDB
initial-access
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗VulnCheck XDB
initial-access
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RIESGO
abrir ↗GitHub PoC★ 1
PoC, Dockerfile playground and root cause from patch diff analysis.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.