Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC2
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
CVE-2026-15469HIGH25 ago 2026
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
41RIESGO
abrir
GitHub PoC
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
CVE-2026-72530CRITICALbajo ataque25 ago 2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
78RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-60004CRITICALbajo ataque25 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC4
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
CVE-2026-32475CRITICAL25 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware25 ago 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
CVE-2026-12295CRITICAL25 ago 2026
Sandbox escape in the DOM: Navigation component
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware25 ago 2026
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-2890625 ago 2026
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet
23RIESGO
abrir
GitHub PoC14
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
CVE-2026-18963CRITICAL25 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
CVE-2026-73570HIGHbajo ataque25 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC35
CVE 1-day in http.sys
CVE-2026-62735HIGH25 ago 2026
Windows HTTP.sys Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL25 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC2
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
CVE-2026-56705CRITICAL25 ago 2026
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RIESGO
abrir
GitHub PoC1
Use cve-2026-36425 killer edr,360 can killer
CVE-2026-36425MEDIUM25 ago 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RIESGO
abrir
GitHub PoC1
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
CVE-2026-58073CRITICAL25 ago 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RIESGO
abrir
GitHub PoC
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
CVE-2026-60004CRITICALbajo ataque25 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
Exploit-DB
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
CVE-2026-42167HIGHremotemultiple25 ago 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RIESGO
abrir
GitHub PoC
khwajasaad267-coder/cve-2024-4577-lab
CVE-2024-4577CRITICALbajo ataqueransomware25 ago 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque24 ago 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-59230MEDIUM24 ago 2026
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RIESGO
abrir
GitHub PoC
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
CVE-2019-0708CRITICALbajo ataqueransomware24 ago 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-76904CRITICAL24 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque24 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC
Patch: Authentication bypass (VMware vCenter)
CVE-2026-11553HIGH24 ago 2026
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RIESGO
abrir
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 ago 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque24 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Patch: OGNL injection (Apache Struts)
CVE-2026-10520CRITICAL24 ago 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
Patch: Remote code execution in SPL parsing (Splunk Enterprise)
CVE-2026-28001CRITICAL24 ago 2026
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
48RIESGO
abrir
anteriorpágina 15 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.