Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 ago 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RIESGO
abrir
GitHub PoC22
Linux Binder binder_free_transaction() process-lifetime use-after-free (CVE-2026-64468): unprivileged PoC + x86_64 LPE. Authorised security research.
CVE-2026-64468HIGH17 ago 2026
binder: fix UAF in binder_free_transaction()
41RIESGO
abrir
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 ago 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RIESGO
abrir
GitHub PoC
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74945MEDIUM17 ago 2026
Information disclosure in the Graphics: Text component
33RIESGO
abrir
Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
CVE-2026-55584HIGHremotelinux17 ago 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RIESGO
abrir
Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
CVE-2026-58058MEDIUMdosmultiple17 ago 2026
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RIESGO
abrir
Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICALwebappsmultiple17 ago 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC4
One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE
CVE-2026-76904CRITICAL16 ago 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RIESGO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 ago 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RIESGO
abrir
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHbajo ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18366CRITICAL16 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir
GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
CVE-2026-71203MEDIUM16 ago 2026
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-6418HIGHbajo ataque16 ago 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
CVE-2026-73519CRITICAL16 ago 2026
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RIESGO
abrir
GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
CVE-2026-8508MEDIUM16 ago 2026
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RIESGO
abrir
GitHub PoC
React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트
CVE-2025-55182CRITICALbajo ataqueransomware16 ago 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
CVE-2026-6837HIGH16 ago 2026
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RIESGO
abrir
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 ago 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RIESGO
abrir
GitHub PoC
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
CVE-2026-72898CRITICALbajo ataque16 ago 2026
Metabase SQL injection via password reset endpoint
100RIESGO
abrir
GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
CVE-2026-71205MEDIUM16 ago 2026
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RIESGO
abrir
GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
CVE-2026-71206HIGH16 ago 2026
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RIESGO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RIESGO
abrir
GitHub PoC3
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
CVE-2026-43499HIGH16 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RIESGO
abrir
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 ago 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RIESGO
abrir
GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
CVE-2026-73633HIGH16 ago 2026
Apache Struts: Unbounded read of a JSON request body
41RIESGO
abrir
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 ago 2026
23RIESGO
abrir
GitHub PoC
ghostpels/CVE-2026-13610
CVE-2026-13610HIGH15 ago 2026
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RIESGO
abrir
anteriorpágina 23 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.