Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.953exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-55993HIGH22 jul 2026
Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour
41RIESGO
abrir
GitHub PoC
CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-58138 - Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator
CVE-2026-58138CRITICAL22 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
CVE-2026-6330MEDIUM22 jul 2026
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RIESGO
abrir
GitHub PoC15
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability detected during a target network scan.
CVE-2012-1823CRITICALbajo ataque22 jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC1
Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.
CVE-2026-41089CRITICAL22 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
ThorVG NULL pointer dereference via malformed SVG — AFL++ fuzzing writeup
CVE-2026-45729MEDIUM22 jul 2026
ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malformed input
33RIESGO
abrir
GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
CVE-2026-63030CRITICALbajo ataque22 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
CVE-2026-16540HIGH22 jul 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RIESGO
abrir
GitHub PoC17
CVE-2026-43499 PoC Scanner
CVE-2026-43499HIGH22 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-50522 - Draft
CVE-2026-50522CRITICALbajo ataque22 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created or supported by Check Point and should be used at your own risk.
CVE-2026-16232CRITICALbajo ataque22 jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding hard-codes muteException=false, so a configured muteException=true is ignored and an uncaught exception's full stack trace is returned to the client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-56139MEDIUM22 jul 2026
Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients
33RIESGO
abrir
GitHub PoC4
Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC6
jaf0rk/CVE-2026-9973-exploit
CVE-2026-9973HIGH21 jul 2026
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code i
41RIESGO
abrir
GitHub PoC
Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.
CVE-2026-45585MEDIUM21 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC27
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.
CVE-2026-41089CRITICAL21 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC1
gigachadusers/CVE-2026-20169
CVE-2026-20169MEDIUM21 jul 2026
Cisco IoT Field Network Director Command Injection Vulnerability
33RIESGO
abrir
GitHub PoC1
a shitty poc utilizing CVE-2026-0059.
CVE-2026-0059HIGH21 jul 2026
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl
41RIESGO
abrir
GitHub PoC2
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
CVE-2026-60137MEDIUMbajo ataque21 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC1
0xdak/CVE-2026-9198_exploit
CVE-2026-9198CRITICALbajo ataque21 jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
98RIESGO
abrir
GitHub PoC
CVE-2026-43499
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC11
CVE-2026-52910 kernel crash PoC. screen goes off.
CVE-2026-52910HIGH21 jul 2026
bpf: Free reuseport cBPF prog after RCU grace period.
41RIESGO
abrir
GitHub PoC
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
CVE-2026-60137MEDIUMbajo ataque21 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC1
CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive version scanner. No weaponized PoC.
CVE-2026-52813CRITICAL21 jul 2026
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RIESGO
abrir
GitHub PoC
CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-13156MEDIUM21 jul 2026
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RIESGO
abrir
GitHub PoC
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
CVE-2026-13233LOW21 jul 2026
OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
28RIESGO
abrir
GitHub PoC
OnePlus Ace 3 preload.so for CVE-2026-43499 (GhostLock)
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49365MEDIUM21 jul 2026
Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients
33RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.