Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
Begitdj/cve-2019-2215-markw
CVE-2019-2215HIGHbajo ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC
open-flaw/CVE-2026-56848
CVE-2026-56848HIGH19 ago 2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RIESGO
abrir
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
CVE-2025-24893CRITICALbajo ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL19 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL19 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC
CVE-2026-47858
CVE-2026-47858HIGH19 ago 2026
live information startup mode is vulnerable for remote code execution
41RIESGO
abrir
GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE-2026-15748CRITICAL19 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque19 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque19 ago 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-34486HIGHbajo ataque19 ago 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque19 ago 2026
Incorrect Authorization in Graphics
71RIESGO
abrir
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALbajo ataqueransomware19 ago 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
GitHub PoC532
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALbajo ataqueransomware19 ago 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC1
CVE-2026-39987 — Marimo Pre-Authentication RCE
CVE-2026-39987CRITICALbajo ataque19 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
CVE-2021-42013CRITICALbajo ataqueransomware19 ago 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RIESGO
abrir
GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
CVE-2026-18504MEDIUM19 ago 2026
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RIESGO
abrir
GitHub PoC
zavisco/CVE-2026-64849.yaml
CVE-2026-64849CRITICALbajo ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir
GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
CVE-2026-63030CRITICALbajo ataque19 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALbajo ataque19 ago 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RIESGO
abrir
GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
CVE-2026-54121HIGH19 ago 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-64849 PoC
CVE-2026-64849CRITICALbajo ataque19 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir
GitHub PoC1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
CVE-2026-53365HIGH19 ago 2026
vsock/virtio: fix zerocopy completion for multi-skb sends
41RIESGO
abrir
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 ago 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RIESGO
abrir
anteriorpágina 20 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.