Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-60093MEDIUM24 ago 2026
Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque24 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-76904CRITICAL24 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
GitHub PoC2
T0w0T/POC-CVE-2026-18963
CVE-2026-18963CRITICAL24 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-20333CRITICALbajo ataque24 ago 2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu
100RIESGO
abrir
GitHub PoC2
CVE-2026-77806漏洞检测代码
CVE-2026-77806CRITICAL24 ago 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
CVE-2025-55182CRITICALbajo ataqueransomware24 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Patch: SSRF leading to RCE (Microsoft Exchange Server)
CVE-2026-15502MEDIUM24 ago 2026
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
33RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
CVE-2026-66908HIGH24 ago 2026
Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
41RIESGO
abrir
GitHub PoC1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
CVE-2026-74939HIGH24 ago 2026
Privilege escalation in the DOM: Navigation component
41RIESGO
abrir
GitHub PoC20
CVE-2026-18963
CVE-2026-18963CRITICAL24 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
CVE-2026-78329CRITICAL24 ago 2026
Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
48RIESGO
abrir
GitHub PoC
Patch: Authentication bypass (VMware vCenter)
CVE-2026-11553HIGH24 ago 2026
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RIESGO
abrir
GitHub PoC
Patch: OGNL injection (Apache Struts)
CVE-2026-10520CRITICAL24 ago 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL24 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-63621MEDIUM24 ago 2026
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot
CVE-2026-71300CRITICAL24 ago 2026
Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66907HIGH24 ago 2026
Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
41RIESGO
abrir
GitHub PoC
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)
CVE-2026-14290MEDIUM24 ago 2026
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL24 ago 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
CVE-2026-28672CRITICAL24 ago 2026
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
48RIESGO
abrir
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 ago 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RIESGO
abrir
GitHub PoC
h00die/POC-CVE-2026-19626
CVE-2026-19626CRITICAL24 ago 2026
Remote Code Execution
63RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-59230MEDIUM24 ago 2026
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66906CRITICAL24 ago 2026
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RIESGO
abrir
GitHub PoC
Patch: Privilege escalation via web UI (Cisco IOS XE)
CVE-2026-19843HIGH24 ago 2026
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
41RIESGO
abrir
GitHub PoC4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
CVE-2026-10053HIGH23 ago 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RIESGO
abrir
GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
CVE-2009-065823 ago 2026
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RIESGO
abrir
GitHub PoC
h00die/POC-CVE-2026-19681
CVE-2026-19681CRITICAL23 ago 2026
Command Injection
63RIESGO
abrir
anteriorpágina 16 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.