Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Dynamo2k1/CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque23 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-56121_exploit
CVE-2026-56121CRITICAL23 jul 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RIESGO
abrir
GitHub PoC11
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
CVE-2026-66804HIGH23 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC1
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
CVE-2026-58057LOW23 jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RIESGO
abrir
GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-41940CRITICALbajo ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
CVE-2026-48546HIGH23 jul 2026
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
41RIESGO
abrir
GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2020-1472MEDIUMbajo ataqueransomware23 jul 2026
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALbajo ataqueransomware23 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2025-55182-react2shell_reproduction
CVE-2025-55182CRITICALbajo ataqueransomware23 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Tproot es una máquina de nivel Muy Fácil de DockerLabs centrada en la explotación manual del servicio vsftpd 2.3.4 (CVE-2011-2523).
CVE-2011-252323 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CVE-2026-45132CRITICAL23 jul 2026
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RIESGO
abrir
GitHub PoC4
soralis0912/CVE-2026-43499-aristotle
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction
CVE-2026-63030CRITICALbajo ataque23 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC5
soralis0912/CVE-2026-43499-aristotle-apk
CVE-2026-43499HIGH23 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
CVE-2021-41773 Apache
CVE-2021-41773HIGHbajo ataqueransomware23 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
CVE-2026-64600 - Draft - Check todo
CVE-2026-64600HIGH23 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC318
Certighost POC
CVE-2026-54121HIGH23 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
CVE-2024-6387HIGH23 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
CVE-2026-41940CRITICALbajo ataqueransomware23 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
CVE-2025-2783HIGHbajo ataque23 jul 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RIESGO
abrir
GitHub PoC
CVE-2026-42533 Nginx
CVE-2026-42533CRITICAL23 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC
CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)
CVE-2026-66374HIGH23 jul 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
41RIESGO
abrir
GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
CVE-2026-23744CRITICAL23 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC15
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.18.3/4.21.0.
CVE-2026-55994HIGH22 jul 2026
Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour
41RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-55993HIGH22 jul 2026
Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour
41RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding hard-codes muteException=false, so a configured muteException=true is ignored and an uncaught exception's full stack trace is returned to the client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-56139MEDIUM22 jul 2026
Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients
33RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.