Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
14.316 exploits
GitHub PoC
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.
Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users
33RIESGO
abrir ↗GitHub PoC
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.
Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic
33RIESGO
abrir ↗GitHub PoC
CVE-2026-60121, CVE-2026-61498 - Draft
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
48RIESGO
abrir ↗GitHub PoC
Dungsocool/CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir ↗GitHub PoC
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir ↗GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 16
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour
33RIESGO
abrir ↗GitHub PoC
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 313
A cPanel and WHM authentication bypassing tool
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir ↗GitHub PoC★ 1
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 204
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir ↗GitHub PoC★ 1
PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange headers, hijacking the tool route's exec: sink for RCE. Fixed in 4.14.8/4.18.3/4.21.0.
Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
41RIESGO
abrir ↗GitHub PoC★ 4
WordPress REST API SQLi to RCE (CVE-2026-63030)
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 2
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
Apache Syncope: User self-service privilege escalation
Apache Syncope: User self-service privilege escalation
48RIESGO
abrir ↗GitHub PoC
Detection script for CVE-2026-11374
Account Takeover via Predictable SSO Ticket Generation
48RIESGO
abrir ↗GitHub PoC
Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗GitHub PoC★ 5
PoC for CVE-2026-12191
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RIESGO
abrir ↗GitHub PoC
HELLBOY3110/cve-2026-16219-croogo-lab
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
33RIESGO
abrir ↗GitHub PoC
Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue operations with the endpoint's service-account credentials (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
33RIESGO
abrir ↗GitHub PoC★ 1
joaovicdev/EXPLOIT-CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
41RIESGO
abrir ↗GitHub PoC
Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-63030 / wp2shell
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.