Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC
open-flaw/CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RIESGO
abrir ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RIESGO
abrir ↗VulnCheck XDB
info-leak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RIESGO
abrir ↗GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RIESGO
abrir ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-19500 poc
SureForms contains an uncontrolled resource consumption vulnerability
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗VulnCheck XDB
local
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consid
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
85RIESGO
abrir ↗GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
ksotaria1337/CVE-2026-19598
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir ↗GitHub PoC
kaleth4/CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RIESGO
abrir ↗GitHub PoC★ 1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
Microsoft Defender Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RIESGO
abrir ↗GitHub PoC★ 11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗GitHub PoC★ 10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
Improper Control of Generation of Code ('Code Injection') in GitLab
63RIESGO
abrir ↗GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.