Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC
open-flaw/CVE-2026-56848
CVE-2026-56848HIGH19 ago 2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque19 ago 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-34486HIGHbajo ataque19 ago 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RIESGO
abrir
Exploit-DB
PCMan 2.0.7 - Buffer Overflow
CVE-2025-4871MEDIUMremotewindows18 ago 2026
PCMan FTP Server REST Command buffer overflow
33RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2014-0160HIGHbajo ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
CVE-2014-0160HIGHbajo ataque18 ago 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
CVE-2026-44848CRITICAL18 ago 2026
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RIESGO
abrir
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849CRITICALbajo ataque18 ago 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC3
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
CVE-2026-14669HIGH18 ago 2026
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-62593CRITICALbajo ataque18 ago 2026
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RIESGO
abrir
GitHub PoC1
CVE-2026-19500 poc
CVE-2026-19500HIGH18 ago 2026
SureForms contains an uncontrolled resource consumption vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL18 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir
VulnCheck XDB
local
CVE-2015-180518 ago 2026
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consid
23RIESGO
abrir
GitHub PoC
CVE-2026-19501 poc
CVE-2026-19501HIGH18 ago 2026
CVE-2026-19501
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20079CRITICAL18 ago 2026
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
85RIESGO
abrir
GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-43499HIGH18 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
ksotaria1337/CVE-2026-19598
CVE-2026-19598CRITICAL18 ago 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir
GitHub PoC
kaleth4/CVE-2026-64638
CVE-2026-64638HIGH18 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
GitHub PoC3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
CVE-2026-15748CRITICAL18 ago 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RIESGO
abrir
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 ago 2026
Path Traversal Vulnerability in apport-unpack
33RIESGO
abrir
GitHub PoC3
CVE-2026-65400
CVE-2026-65400CRITICALbajo ataque18 ago 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RIESGO
abrir
GitHub PoC11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALbajo ataque18 ago 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
CVE-2026-19478CRITICAL18 ago 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir
GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
CVE-2026-9254HIGH18 ago 2026
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RIESGO
abrir
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 ago 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RIESGO
abrir
anteriorpágina 21 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.