Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.955exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC2
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
CVE-2026-60137MEDIUMbajo ataque21 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)
CVE-2026-30623CRITICAL21 jul 2026
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application
63RIESGO
abrir
GitHub PoC
mass_cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware21 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
PoC toolkit for exploiting Cisco IMC RCE CVE-2026-20200
CVE-2026-20200HIGH21 jul 2026
Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC1
CVE-2026-6875
CVE-2026-6875CRITICAL21 jul 2026
Sandbox Escape in ServiceNow AI Platform
68RIESGO
abrir
GitHub PoC
Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow
CVE-2026-42533CRITICAL21 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate credentials, and test time-based blind injection. For authorized security research. Author: Sudeepa Wanigarathna. Patched in 10.12.1.
CVE-2026-57588LOW21 jul 2026
SQL Injection in Nessus via Malicious Scan Result File Import
28RIESGO
abrir
GitHub PoC
CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-13156MEDIUM21 jul 2026
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RIESGO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2021-22555
CVE-2021-22555HIGHbajo ataque21 jul 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC
danielissaq/-PaperCut-CVE-2023-27350-
CVE-2023-27350CRITICALbajo ataqueransomware21 jul 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
GitHub PoC1
Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863
CVE-2026-8863HIGH21 jul 2026
CVE-2026-8863
41RIESGO
abrir
GitHub PoC1
CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive version scanner. No weaponized PoC.
CVE-2026-52813CRITICAL21 jul 2026
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RIESGO
abrir
GitHub PoC11
CVE-2026-52910 kernel crash PoC. screen goes off.
CVE-2026-52910HIGH21 jul 2026
bpf: Free reuseport cBPF prog after RCU grace period.
41RIESGO
abrir
GitHub PoC1
PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required roles/permissions the token is never verified, so any forged/garbage bearer token bypasses authentication (unauthenticated RCE). Fixed in 4.18.3/4.21.0.
CVE-2026-53913CRITICAL21 jul 2026
Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted
48RIESGO
abrir
GitHub PoC
WhatsWrongAndWhy/CVE-2017-7308
CVE-2017-730821 jul 2026
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access control). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49099MEDIUM21 jul 2026
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
33RIESGO
abrir
GitHub PoC
Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.
CVE-2026-45585MEDIUM21 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC1
a shitty poc utilizing CVE-2026-0059.
CVE-2026-0059HIGH21 jul 2026
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl
41RIESGO
abrir
GitHub PoC27
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.
CVE-2026-41089CRITICAL21 jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC6
jaf0rk/CVE-2026-9973-exploit
CVE-2026-9973HIGH21 jul 2026
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code i
41RIESGO
abrir
GitHub PoC
CVE-2026-43499
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC4
Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
OnePlus Ace 3 preload.so for CVE-2026-43499 (GhostLock)
CVE-2026-43499HIGH21 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
gigachadusers/CVE-2026-20169
CVE-2026-20169MEDIUM21 jul 2026
Cisco IoT Field Network Director Command Injection Vulnerability
33RIESGO
abrir
GitHub PoC1
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
0x00phantom-hat/CVE-2026-5029-Exploit
CVE-2026-5029HIGH20 jul 2026
RCE in Code Runner MCP Server
41RIESGO
abrir
GitHub PoC16
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
CVE-2026-45585MEDIUM20 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
CVE-2026-4858 research
CVE-2026-4858HIGH20 jul 2026
Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.
21RIESGO
abrir
GitHub PoC5
PoC for CVE-2026-12191
CVE-2026-12191HIGH20 jul 2026
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RIESGO
abrir
GitHub PoC2
noLKM,5.10 use CVE-2026-52910.
CVE-2026-52910HIGH20 jul 2026
bpf: Free reuseport cBPF prog after RCU grace period.
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.