Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.858 exploits
Exploit-DB
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CVE-2026-58138CRITICALwebappsmultiple10 ago 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
GitHub PoC
unpredictable21/halo-cors-csrf-CVE-2026-67921
CVE-2026-67921CRITICAL10 ago 2026
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and
48RIESGO
abrir
GitHub PoC4
GhostLock-X200 v1.0 - temporary root toolchain for vivo X200 (PD2415 / b57 kernel) based on CVE-2026-43499. For authorized security research only.
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC25
CVE-2026-53361 AF_UNIX GC vs MSG_PEEK use-after-free container escape
CVE-2026-53361HIGH10 ago 2026
af_unix: Set gc_in_progress to true in unix_gc().
41RIESGO
abrir
GitHub PoC
CVE-2026-43499 GhostLock APK 骨架 — 仅验证空项目能编译通过
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass, JWT_SECRET escalation, and analysis of the upstream fix.
CVE-2026-19264CRITICAL10 ago 2026
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
48RIESGO
abrir
GitHub PoC1
CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29
CVE-2026-43499HIGH10 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free
CVE-2026-64564CRITICAL10 ago 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RIESGO
abrir
GitHub PoC1
IamDremig/CVE-2026-65591
CVE-2026-65591HIGH10 ago 2026
n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
41RIESGO
abrir
GitHub PoC
Procjevt/CVE-2026-9198
CVE-2026-9198CRITICALbajo ataque10 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC2
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.
CVE-2026-23744CRITICAL10 ago 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
Proof of Concept (PoC) WebSocket client for CVE-2026-39987 (Marimo Pre-Auth RCE), intended for authorized security testing.
CVE-2026-39987CRITICALbajo ataque10 ago 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
Authorized Kali–Metasploitable2 lab using Python and Nmap NSE to validate CVE-2011-2523 in vsFTPd 2.3.4.
CVE-2011-252310 ago 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
POC 4 CVE-2026-15038
CVE-2026-15038CRITICAL09 ago 2026
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
48RIESGO
abrir
GitHub PoC3
eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque09 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC6
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)
CVE-2026-34910CRITICALbajo ataque09 ago 2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS
100RIESGO
abrir
GitHub PoC1
CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.
CVE-2026-69084CRITICAL09 ago 2026
SiYuan before v3.7.3 SQL Injection via searchEmbedBlock
63RIESGO
abrir
GitHub PoC
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB
CVE-2025-59528CRITICAL09 ago 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials.
CVE-2026-63030CRITICALbajo ataque09 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware09 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.
CVE-2017-8464HIGHbajo ataque09 ago 2026
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC1
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
GitHub PoC
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
GitHub PoC3
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
CVE-2026-64638HIGH09 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8464HIGHbajo ataque09 ago 2026
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC
Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.
CVE-2026-9645CRITICAL09 ago 2026
ScadaBR Authenticated Remote Code Execution
48RIESGO
abrir
GitHub PoC1
Windwos Zero Day Local PrivESc Exploit (CVE-2026-41091)
CVE-2026-41091HIGHbajo ataque09 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC1
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
CVE-2021-44228CRITICALbajo ataqueransomware09 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
anteriorpágina 29 / 2662siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.