Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
GitHub PoC
CVE-2026-69836 - Draft or TODO
CVE-2026-69836CRITICAL21 ago 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC5
CVE-2026-73570
CVE-2026-73570HIGHbajo ataque21 ago 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
CVE-2026-76036CRITICAL21 ago 2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHbajo ataque21 ago 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RIESGO
abrir
GitHub PoC1
elkhaoudari/CVE-2018-7600-PoC
CVE-2018-7600CRITICALbajo ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC40
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
CVE-2026-18366CRITICAL20 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir
GitHub PoC
🧪 Measures memory-poisoning / prompt-injection deterministically — anchored to CVE-2026-24301 (CoSnitch), Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 ago 2026
Microsoft Copilot Information Disclosure Vulnerability
41RIESGO
abrir
VulnCheck XDB
local
CVE-2022-38181HIGHbajo ataque20 ago 2026
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RIESGO
abrir
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 ago 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RIESGO
abrir
GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
CVE-2026-18315CRITICAL20 ago 2026
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 ago 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18366CRITICAL20 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALbajo ataqueransomware20 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC15
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALbajo ataque20 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware20 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHbajo ataque20 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RIESGO
abrir
GitHub PoC
This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive shell.
CVE-2026-39987CRITICALbajo ataque20 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque20 ago 2026
Incorrect Authorization in Graphics
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL20 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque20 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
CVE-2010-207520 ago 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
CVE-2026-71960CRITICAL20 ago 2026
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware19 ago 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
anteriorpágina 19 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.