Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC★ 1
Begitdj/cve-2019-2215-markw
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗GitHub PoC★ 1
renzi25031469/CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗GitHub PoC
open-flaw/CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RIESGO
abrir ↗GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗GitHub PoC
CVE-2026-47858
live information startup mode is vulnerable for remote code execution
41RIESGO
abrir ↗GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RIESGO
abrir ↗VulnCheck XDB
initial-access
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir ↗GitHub PoC★ 532
A cPanel and WHM authentication bypassing tool
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-39987 — Marimo Pre-Authentication RCE
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 1
0xdeadroot/SCTPhantom-CVE-2026-64564
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RIESGO
abrir ↗GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RIESGO
abrir ↗GitHub PoC
zavisco/CVE-2026-64849.yaml
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RIESGO
abrir ↗GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC
CVE-2026-64849 PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗GitHub PoC★ 1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
vsock/virtio: fix zerocopy completion for multi-skb sends
41RIESGO
abrir ↗GitHub PoC★ 1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
Kernel driver vulnerability in Safetica Endpoint Client
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.