Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
CVE-2026-60206CRITICAL25 jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RIESGO
abrir
GitHub PoC5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
CVE-2026-43499HIGH25 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
CVE-2026-12960MEDIUM25 jul 2026
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
33RIESGO
abrir
GitHub PoC
Auth Bypass in inetutils-telnetd
CVE-2026-24061CRITICALbajo ataque25 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
CVE-2026-43499HIGH25 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
CVE-2026-48908CRITICAL25 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
CVE-2026-65694HIGH25 jul 2026
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RIESGO
abrir
GitHub PoC39
CVE-2026-50522 PoC
CVE-2026-50522CRITICALbajo ataque25 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2026-54121 - Draft
CVE-2026-54121HIGH25 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Manage BitLocker encrypted drives on Windows 10 and 11. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
Security Advisory for CVE-2026-51564
CVE-2026-51564MEDIUM25 jul 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RIESGO
abrir
GitHub PoC1
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
CVE-2026-14266HIGH25 jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
CVE-2026-54900MEDIUM25 jul 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RIESGO
abrir
GitHub PoC
Security Advisory for CVE-2026-51565
CVE-2026-51565MEDIUM25 jul 2026
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker
33RIESGO
abrir
GitHub PoC2
CVE-2026-54121
CVE-2026-54121HIGH25 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CypherHippie/CVE-2026-66804
CVE-2026-66804HIGH25 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC3
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
CVE-2026-63030CRITICALbajo ataque25 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass
CVE-2026-9198CRITICALbajo ataque24 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC1
IBM Langflow Unauthenticated RCE via Auto-Login Bypass
CVE-2026-9198CRITICALbajo ataque24 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC
manfredgabriel/cve-2021-43798-lab
CVE-2021-43798HIGHbajo ataque24 jul 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Reproduction of cve-2025-0282-ivanti_rce_reproduction
CVE-2025-0282CRITICALbajo ataqueransomware24 jul 2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC2
CVE-2026-60206
CVE-2026-60206CRITICAL24 jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RIESGO
abrir
GitHub PoC
WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque24 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)
CVE-2026-46331HIGH24 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC
sbimoxa/cve-2021-43798-lab
CVE-2021-43798HIGHbajo ataque24 jul 2026
Grafana path traversal
100RIESGO
abrir
GitHub PoC
risorse di ricerca per cve-2026-7228
CVE-2026-7228MEDIUM24 jul 2026
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-65650 - Elgg avatar upload DoS
CVE-2026-65650MEDIUM24 jul 2026
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
33RIESGO
abrir
GitHub PoC1
React2Shell is a proof-of-concept exploit for CVE-2025-55182 affecting vulnerable React Server Components (RSC) implementations in Next.js
CVE-2025-55182CRITICALbajo ataqueransomware24 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
kxom9ks/CVE-2024-27198-TeamCity
CVE-2024-27198CRITICALbajo ataqueransomware24 jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.