Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
14.946 exploits
GitHub PoC★ 10
GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15) 声明,由于 AI 过于弱智 导致大量 token 被消耗 这导致资金严重不足在短时间内将不会更新 下次更新最早两天后
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-52680_exploit
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RIESGO
abrir ↗GitHub PoC
🚨 Threat intel & incident response research on SharePoint "ToolShell" RCE zero-day (CVE-2025-53770). 🕵️♂️ Covers root-cause deserialization flaws, attack timelines, risk metrics, and defensive EDR validation playbooks. 🛡️
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir ↗GitHub PoC★ 1
showmeyourhands/CVE-2026-52102-PoC
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe
48RIESGO
abrir ↗GitHub PoC
webshellseo8/CVE-2026-12720-Proof-of-Concept
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
41RIESGO
abrir ↗GitHub PoC
python code use to check for user in ssh
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11112-XXE-via-SVG-Image-Upload
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remo
48RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
48RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform U
33RIESGO
abrir ↗GitHub PoC
Foxer131/CVE-2026-70481
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
33RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri
33RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec
41RIESGO
abrir ↗GitHub PoC★ 3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 1
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a rem
48RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11117-WPA2-4-Way-Handshake-Reinstallation-KRACK-Sim-
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar
41RIESGO
abrir ↗GitHub PoC
CVE-2026-13934
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RIESGO
abrir ↗GitHub PoC
CVE-2026-13934
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-67340_exploit
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
41RIESGO
abrir ↗GitHub PoC★ 5
WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030 (wp2shell).
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RIESGO
abrir ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2021-41773-Exploit
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code
41RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-leve
41RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-11114-Node.js-vm-Sandbox-Escape-via-Proxy
Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromi
48RIESGO
abrir ↗GitHub PoC
George0Papasotiriou/CVE-2026-21017-LDAP-Anonymous-Bind-Privilege-Escalation
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack
33RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-59243_exploit
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RIESGO
abrir ↗GitHub PoC
0xdak/CVE-2026-14483_exploit
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.