Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
CVE-2026-9999HIGH03 ago 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RIESGO
abrir
GitHub PoC2
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CVE-2026-63223CRITICAL03 ago 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-8888-Printer-Firmware-Unsigned-Update-via-HTTP
CVE-2026-8888HIGH03 ago 2026
CVE-2026-8888
41RIESGO
abrir
GitHub PoC
CVE-2026-17583 - Draft
CVE-2026-17583HIGH03 ago 2026
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11101-HTTP-Cache-Poisoning-via-Unkeyed-Query-Parameter
CVE-2026-11101MEDIUM03 ago 2026
Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-ori
33RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking
CVE-2026-11102HIGH03 ago 2026
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to e
41RIESGO
abrir
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALbajo ataque03 ago 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
CVE-2026-11104MEDIUM03 ago 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RIESGO
abrir
GitHub PoC
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
CVE-2026-54121HIGH03 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
CVE-2026-45585MEDIUM03 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
CVE-2017-1263503 ago 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-69083_exploit
CVE-2026-69083CRITICAL03 ago 2026
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RIESGO
abrir
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
CVE-2026-16723CRITICAL03 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC2
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
CVE-2026-64531HIGH03 ago 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-
CVE-2026-6666MEDIUM03 ago 2026
PgBouncer crash in kill_pool_logins_server_error
33RIESGO
abrir
GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
CVE-2026-52887CRITICAL03 ago 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RIESGO
abrir
GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
CVE-2026-48710MEDIUM03 ago 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RIESGO
abrir
GitHub PoC
Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)
CVE-2026-43637HIGH03 ago 2026
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
41RIESGO
abrir
GitHub PoC
siboy17/CVE-2022-21907-http.sys
CVE-2022-21907CRITICAL03 ago 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.
CVE-2026-12940CRITICAL03 ago 2026
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
48RIESGO
abrir
GitHub PoC1
CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque03 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC32
villager1314/CVE-2026-64560-Analysis
CVE-2026-64560HIGH03 ago 2026
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
CVE-2026-3891CRITICAL03 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection
CVE-2026-9997HIGH03 ago 2026
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende
41RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-68771_exploit
CVE-2026-68771CRITICAL03 ago 2026
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
48RIESGO
abrir
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 ago 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RIESGO
abrir
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALbajo ataqueransomware03 ago 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC2
Kangaroo is a exploit built on CVE-2026-32746. i made this for security researchers, IT professionals, DevOps. so they can understand it better. DO NOT USE THIS FOR ILLEGAL USE, IF YOU DO... YOU MAY BE SUBJECT TO ARREST, AND FINES.
CVE-2026-32746CRITICAL02 ago 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir
GitHub PoC
Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint to read arbitrary system files.
CVE-2024-40422CRITICAL02 ago 2026
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
GitHub PoC
CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.
CVE-2026-9806MEDIUM02 ago 2026
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
33RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.