Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC1
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
CVE-2026-54121HIGH31 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALbajo ataque31 jul 2026
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
GitHub PoC2
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066CRITICAL31 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC
Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass
CVE-2026-17351CRITICAL31 jul 2026
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
48RIESGO
abrir
GitHub PoC1
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALbajo ataque30 jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
98RIESGO
abrir
GitHub PoC
CVE-2026-63030 Exploit | by gr1tx
CVE-2026-63030CRITICALbajo ataque30 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Fastjson RCE
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC2
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
CVE-2026-57827CRITICAL30 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir
GitHub PoC
shootcannon/CVE-2026-61511
CVE-2026-61511CRITICAL30 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
GitHub PoC
Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)
CVE-2026-66418CRITICAL30 jul 2026
OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field
48RIESGO
abrir
GitHub PoC2
Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.
CVE-2025-64446CRITICALbajo ataque30 jul 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RIESGO
abrir
GitHub PoC2
Nowafen/CVE-2026-16723
CVE-2026-16723CRITICAL30 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
CVE-2026-61424CRITICAL30 jul 2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
48RIESGO
abrir
GitHub PoC
HeltonPojo/CVE-2025-32432
CVE-2025-32432CRITICALbajo ataque30 jul 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-59726 - Draft or Todo
CVE-2026-59726CRITICAL30 jul 2026
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
48RIESGO
abrir
GitHub PoC25
rails/rails-forensics-CVE-2026-66066
CVE-2026-66066CRITICAL30 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
48RIESGO
abrir
GitHub PoC
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
CVE-2024-28000CRITICAL30 jul 2026
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RIESGO
abrir
GitHub PoC
KunalKhandelwal-dev/cve-2021-41773-lab
CVE-2021-41773HIGHbajo ataqueransomware30 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
CVE-2026-10702
CVE-2026-10702MEDIUM30 jul 2026
JIT miscompilation in the JavaScript Engine: JIT component
33RIESGO
abrir
GitHub PoC
Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 | aimy_captcha-less_form_guard < 20.1
CVE-2026-65883CRITICAL30 jul 2026
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
48RIESGO
abrir
GitHub PoC
Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)
CVE-2026-66421HIGH30 jul 2026
OpenClaw Dashboard Stored XSS via lastMessage Session Field
41RIESGO
abrir
GitHub PoC
nawalacheker1/CVE-2026-46331
CVE-2026-46331HIGH30 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
CVE-2026-58025MEDIUM29 jul 2026
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RIESGO
abrir
GitHub PoC9
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
CVE-2026-43813HIGH29 jul 2026
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
41RIESGO
abrir
GitHub PoC
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RIESGO
abrir
GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
CVE-2026-52134CRITICAL29 jul 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RIESGO
abrir
GitHub PoC1
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-45746CRITICAL29 jul 2026
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RIESGO
abrir
GitHub PoC
CamilleGR/CVE-2026-73292
CVE-2026-73292HIGH29 jul 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
41RIESGO
abrir
GitHub PoC
Pravin761/CVE-2026-54107
CVE-2026-54107HIGH29 jul 2026
Windows Win32k Elevation of Privilege Vulnerability
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.