Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59941MEDIUM02 ago 2026
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
33RIESGO
abrir
GitHub PoC
VMware vCenter Server CVE-2021-21972 (RCE) — vulnerability analysis, detection, and mitigation
CVE-2021-21972CRITICALbajo ataqueransomware02 ago 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir
GitHub PoC
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2026-13714CRITICAL02 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RIESGO
abrir
GitHub PoC170
Jailbreak supported Google Pixel phones with CVE-2026-43499
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-9809 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).
CVE-2026-9809HIGH02 ago 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project
41RIESGO
abrir
GitHub PoC3
CVE-2026-43499 for the Meta Quest
CVE-2026-43499HIGH02 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PHP payloads.
CVE-2026-49049HIGH02 ago 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
61RIESGO
abrir
GitHub PoC
CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.
CVE-2026-9806MEDIUM02 ago 2026
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
33RIESGO
abrir
GitHub PoC9
Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.
CVE-2026-57827CRITICAL02 ago 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir
GitHub PoC2
Kangaroo is a exploit built on CVE-2026-32746. i made this for security researchers, IT professionals, DevOps. so they can understand it better. DO NOT USE THIS FOR ILLEGAL USE, IF YOU DO... YOU MAY BE SUBJECT TO ARREST, AND FINES.
CVE-2026-32746CRITICAL02 ago 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir
GitHub PoC
CVE-2026-9811 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).
CVE-2026-9811MEDIUM02 ago 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s
33RIESGO
abrir
GitHub PoC2
A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying the repository’s configured approval gates.
CVE-2026-58424HIGH02 ago 2026
Permanent Fork PR Workflow Approval Gate Bypass
41RIESGO
abrir
GitHub PoC
Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint to read arbitrary system files.
CVE-2024-40422CRITICAL02 ago 2026
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RIESGO
abrir
GitHub PoC1
TryHackMe Dirty Frag (CVE-2026-43284) — Linux LPE writeup
CVE-2026-43284HIGH02 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
CVE-2026-8239MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
33RIESGO
abrir
GitHub PoC
raihants/cve-2026-10702
CVE-2026-10702MEDIUM01 ago 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RIESGO
abrir
GitHub PoC1
This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.
CVE-2018-999501 ago 2026
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
PD2229B的43499(ghostlock)可行性研究
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)
CVE-2026-15964CRITICAL01 ago 2026
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
48RIESGO
abrir
GitHub PoC168
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
CVE-2026-45585MEDIUM01 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
CVE-2026-8237MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
48RIESGO
abrir
GitHub PoC
System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.
CVE-2011-252301 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and filesystem IOCs, verifies core integrity, and exports evidence. Optional controlled account cleanup; does not remove malware.
CVE-2026-60137MEDIUMbajo ataque01 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and LLMNR/NBT-NS credential poisoning — each with step-by-step packet analysis, screenshots, and a full Wireshark filter/command reference. Personal SOC Analyst Tier 1 learning log.
CVE-2024-27198CRITICALbajo ataqueransomware01 ago 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC1
Wolf CMS <= 0.8.3.1 - RCE via Arbitrary File Write
CVE-2026-67206HIGH01 ago 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RIESGO
abrir
GitHub PoC7
Root prototype for Galaxy S26 (SM-S942U) that is very much indev
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
CVE-2026-64531
CVE-2026-64531HIGH01 ago 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC1
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
CVE-2026-13152HIGH01 ago 2026
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
41RIESGO
abrir
GitHub PoC
aj2108/CVE-2026-9833
CVE-2026-9833HIGH01 ago 2026
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.