Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.697exploits catalogados
36.715CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.264GitHub PoC 15.172VulnCheck XDB 8920Nuclei 4373Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.697 exploits
VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
katranSefa/CVE-2026-19949
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
41RIESGO
abrir ↗GitHub PoC
este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗VulnCheck XDB
initial-access
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir ↗GitHub PoC
0xCyp1337/CVE-2026-44402
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
48RIESGO
abrir ↗GitHub PoC★ 30
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir ↗VulnCheck XDB
initial-access
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RIESGO
abrir ↗VulnCheck XDB
initial-access
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir ↗VulnCheck XDB
initial-access
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir ↗GitHub PoC★ 2
adriyansyah-mf/cve-2026-85046-poc
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir ↗GitHub PoC
LeotheGGman/Langflow-RCE-CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗GitHub PoC
Exploit Framework for CVE-2025-4255
PCMan FTP Server RMD Command buffer overflow
33RIESGO
abrir ↗GitHub PoC
A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir ↗GitHub PoC
V8 TurboFan CheckMaps type-confusion research and compressed-heap R/W exploit notes for CVE-2026-78938.
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
41RIESGO
abrir ↗GitHub PoC
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
48RIESGO
abrir ↗GitHub PoC
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in indepen
41RIESGO
abrir ↗GitHub PoC
AppleAVE2 kernel driver wire-format research and macOS reachability PoC for CVE-2026-64747.
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RIESGO
abrir ↗GitHub PoC
Keycloak Blind SSRF POC
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RIESGO
abrir ↗GitHub PoC★ 7
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RIESGO
abrir ↗GitHub PoC
katranSefa/CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir ↗GitHub PoC
katranSefa/CVE-2026-3891
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗GitHub PoC
postgres CVE-2026-6471 Exploit
PostgreSQL logical decoding can dlopen arbitrary file
41RIESGO
abrir ↗GitHub PoC
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir ↗GitHub PoC
0xCyp1337/CVE-2026-19598-
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗GitHub PoC
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.