Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
PD2229B的43499(ghostlock)可行性研究
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.
CVE-2021-44228CRITICALbajo ataqueransomware01 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
CVE-2026-43499HIGH01 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-14483 POC EXPLOIT BY MADEXPLOITS
CVE-2026-14483CRITICAL01 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RIESGO
abrir
GitHub PoC
RichardKabuto/CVE-2026-52370
CVE-2026-52370MEDIUM01 ago 2026
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu
13RIESGO
abrir
GitHub PoC
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
CVE-2026-8237MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
48RIESGO
abrir
GitHub PoC
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
CVE-2026-12478MEDIUM01 ago 2026
Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)
33RIESGO
abrir
GitHub PoC168
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
CVE-2026-45585MEDIUM01 ago 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
CVE-2026-14361MEDIUM01 ago 2026
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
33RIESGO
abrir
GitHub PoC
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
CVE-2026-8239MEDIUM01 ago 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
33RIESGO
abrir
GitHub PoC
raihants/cve-2026-10702
CVE-2026-10702MEDIUM01 ago 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RIESGO
abrir
GitHub PoC
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.
CVE-2026-67595CRITICAL01 ago 2026
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
48RIESGO
abrir
GitHub PoC1
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
CVE-2024-23897CRITICALbajo ataqueransomware31 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
CVE-2026-63563MEDIUM31 jul 2026
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
33RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALbajo ataqueransomware31 jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALbajo ataque31 jul 2026
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC1
This is N-day patch we releasing by testing our model capabilities
CVE-2026-16723CRITICAL31 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC
Unauthenticated RCE in DBGate <= 7.1.8
CVE-2026-47668CRITICAL31 jul 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RIESGO
abrir
GitHub PoC1
mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
CVE-2026-64531HIGH31 jul 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALbajo ataqueransomware31 jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC4
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
CVE-2026-54121HIGH31 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Authenticated Blind OS Command Injection in ClearOS
CVE-2026-67599HIGH31 jul 2026
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RIESGO
abrir
GitHub PoC2
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066CRITICAL31 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC4
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC10
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass
CVE-2026-17351CRITICAL31 jul 2026
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
48RIESGO
abrir
GitHub PoC3
LuZe0y/pd2425-cve-2026-43499-config
CVE-2026-43499HIGH31 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
CVE-2026-8347LOW31 jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
28RIESGO
abrir
GitHub PoC
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
CVE-2026-43284HIGH31 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection engineering, threat hunting, incident response, and Kubernetes security implications.
CVE-2026-43284HIGH31 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.