Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
initial-access
CVE-2026-65400CRITICALbajo ataque22 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RIESGO
abrir
GitHub PoC
Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)
CVE-2024-49138HIGHbajo ataque22 ago 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2011-252322 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
CVE-2026-32475
CVE-2026-32475CRITICAL22 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-75616, an authenticated OS command injection in TP-Link Archer C20 v6 firmware
CVE-2026-75616HIGH22 ago 2026
Command Injection in Router Web Management Interface
41RIESGO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2004-268722 ago 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir
GitHub PoC
CVE-2026-47630 — NVIDIA Triton Inference Server: arbitrary dlopen via TRITON_BATCH_STRATEGY_PATH
CVE-2026-47630MEDIUM22 ago 2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
33RIESGO
abrir
GitHub PoC
Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass
CVE-2026-74252HIGH22 ago 2026
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
41RIESGO
abrir
GitHub PoC
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.
CVE-2009-118522 ago 2026
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RIESGO
abrir
GitHub PoC
PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)
CVE-2026-67358MEDIUM21 ago 2026
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
33RIESGO
abrir
GitHub PoC1
Custom Content Types and Fields plugin for WordPress
CVE-2026-19598CRITICAL21 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHbajo ataque21 ago 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33032CRITICAL21 ago 2026
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-65400CRITICALbajo ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RIESGO
abrir
GitHub PoC
CVE-2026-69836 - Draft or TODO
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
CVE-2026-76036CRITICAL21 ago 2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL21 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-58455CRITICAL21 ago 2026
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RIESGO
abrir
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RIESGO
abrir
GitHub PoC2
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
CVE-2026-63030CRITICALbajo ataque21 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 ago 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RIESGO
abrir
GitHub PoC8
CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload entries (UPLOAD_ERR_NO_FILE). An unauthenticated attacker can submit a multipart
CVE-2026-32475CRITICAL21 ago 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC
CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer
CVE-2026-39113MEDIUM21 ago 2026
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a
33RIESGO
abrir
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALbajo ataque21 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC7
Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.
CVE-2026-65400CRITICALbajo ataque21 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RIESGO
abrir
GitHub PoC5
CVE-2026-73570
CVE-2026-73570HIGHbajo ataque21 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC1
CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
CVE-2022-36804HIGHbajo ataque21 ago 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
Stored XSS via User-Agent in Admin Order View in PhocaCart
CVE-2026-76564HIGH21 ago 2026
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
41RIESGO
abrir
anteriorpágina 18 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.