Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49097MEDIUM20 jul 2026
Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users
33RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49098MEDIUM20 jul 2026
Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic
33RIESGO
abrir
GitHub PoC
CVE-2026-60121, CVE-2026-61498 - Draft
CVE-2026-60121CRITICAL20 jul 2026
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
48RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC16
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.
CVE-2026-45585MEDIUM20 jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir
GitHub PoC
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49086MEDIUM20 jul 2026
Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour
33RIESGO
abrir
GitHub PoC
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC313
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALbajo ataqueransomware20 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC1
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
0x00phantom-hat/CVE-2026-5029-Exploit
CVE-2026-5029HIGH20 jul 2026
RCE in Code Runner MCP Server
41RIESGO
abrir
GitHub PoC204
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attacker @type reaches loadClass with autoType DISABLED via polymorphic types (@JSONType(seeAlso) / Jackson @JsonSubTypes). Marker-only payloads; safeMode + JDK17 controls.
CVE-2026-16723CRITICAL20 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
48RIESGO
abrir
GitHub PoC1
PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange headers, hijacking the tool route's exec: sink for RCE. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49042HIGH20 jul 2026
Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
41RIESGO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE (CVE-2026-63030)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC2
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Apache Syncope: User self-service privilege escalation
CVE-2026-62183CRITICAL20 jul 2026
Apache Syncope: User self-service privilege escalation
48RIESGO
abrir
GitHub PoC
Detection script for CVE-2026-11374
CVE-2026-11374CRITICAL20 jul 2026
Account Takeover via Predictable SSO Ticket Generation
48RIESGO
abrir
GitHub PoC
Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.
CVE-2021-42013CRITICALbajo ataqueransomware20 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC5
PoC for CVE-2026-12191
CVE-2026-12191HIGH20 jul 2026
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
41RIESGO
abrir
GitHub PoC
HELLBOY3110/cve-2026-16219-croogo-lab
CVE-2026-16219MEDIUM20 jul 2026
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
33RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue operations with the endpoint's service-account credentials (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48206MEDIUM20 jul 2026
Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
33RIESGO
abrir
GitHub PoC1
joaovicdev/EXPLOIT-CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
CVE-2026-42533CRITICAL20 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC2
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
CVE-2026-44680HIGH20 jul 2026
MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
41RIESGO
abrir
GitHub PoC
Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC2
CVE-2026-63030 / wp2shell
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
CVE-2026-3891CRITICAL19 jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.