Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 ago 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 ago 2026
Site isolation issue in the Graphics component
33RIESGO
abrir
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALbajo ataque17 ago 2026
vCenter directory-traversal vulnerability
90RIESGO
abrir
Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICALwebappsmultiple17 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RIESGO
abrir
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 ago 2026
Infinite loop on invalid input in golang.org/x/text
41RIESGO
abrir
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALbajo ataque17 ago 2026
vCenter directory-traversal vulnerability
90RIESGO
abrir
Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
CVE-2026-55584HIGHremotelinux17 ago 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-21479HIGHbajo ataque17 ago 2026
Incorrect Authorization in Graphics
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque17 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-59310CRITICALbajo ataque17 ago 2026
vCenter directory-traversal vulnerability
90RIESGO
abrir
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALbajo ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware17 ago 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RIESGO
abrir
Exploit-DB
webpack_devserver 5.2.5 - CSRF
CVE-2026-14620MEDIUMwebappsmultiple17 ago 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RIESGO
abrir
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 ago 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL17 ago 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware17 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
CVE-2026-74943CRITICAL17 ago 2026
Use-after-free in the Graphics: ImageLib component
48RIESGO
abrir
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 ago 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RIESGO
abrir
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALbajo ataquewebappsmultiple17 ago 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
CVE-2026-15826, CVE-2026-15748
CVE-2026-15826CRITICAL17 ago 2026
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RIESGO
abrir
GitHub PoC
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
CVE-2026-74251CRITICAL17 ago 2026
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
48RIESGO
abrir
GitHub PoC22
Linux Binder binder_free_transaction() process-lifetime use-after-free (CVE-2026-64468): unprivileged PoC + x86_64 LPE. Authorised security research.
CVE-2026-64468HIGH17 ago 2026
binder: fix UAF in binder_free_transaction()
41RIESGO
abrir
GitHub PoC6
A poc and write-up for CVE-2026-40345
CVE-2026-40345HIGH17 ago 2026
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RIESGO
abrir
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 ago 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RIESGO
abrir
Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
CVE-2026-58058MEDIUMdosmultiple17 ago 2026
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RIESGO
abrir
Exploit-DB
D-Link DNS_340L - OS Command Injection
CVE-2024-10914CRITICALremotehardware17 ago 2026
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
Exploit-DB
NanaZip 6.5 - DoS
CVE-2026-55780LOWdoswindows17 ago 2026
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RIESGO
abrir
GitHub PoC
POC for CVE-2026-41042
CVE-2026-41042CRITICAL17 ago 2026
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RIESGO
abrir
anteriorpágina 22 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.