Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.781exploits catalogados
36.771CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
GitHub PoC
0xCyp1337/CVE-2026-19598-
CVE-2026-19598CRITICAL05 sep 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RIESGO
abrir
GitHub PoC
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
CVE-2026-18963CRITICAL05 sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
Keycloak Blind SSRF POC
CVE-2020-1077005 sep 2026
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RIESGO
abrir
GitHub PoC1
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
CVE-2026-32475CRITICAL05 sep 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC6
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)
CVE-2026-32475CRITICAL05 sep 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RIESGO
abrir
GitHub PoC7
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
CVE-2026-64560HIGH05 sep 2026
posix-cpu-timers: Prevent UAF caused by non-leader exec() race
41RIESGO
abrir
GitHub PoC
Root-cause analysis and crash-tier PoC for CVE-2026-64705, an HFS xattr kernel heap overflow on macOS.
CVE-2026-64705MEDIUM05 sep 2026
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma
33RIESGO
abrir
GitHub PoC
V8 TurboFan CheckMaps type-confusion research and compressed-heap R/W exploit notes for CVE-2026-78938.
CVE-2026-78938HIGH05 sep 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
41RIESGO
abrir
GitHub PoC
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
CVE-2026-75865CRITICAL05 sep 2026
WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
48RIESGO
abrir
GitHub PoC1
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
CVE-2026-41940CRITICALbajo ataqueransomware05 sep 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
katranSefa/CVE-2026-3891
CVE-2026-3891CRITICAL05 sep 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC
cve-2026-19900-PoC
CVE-2026-19900CRITICAL04 sep 2026
LB-LINK X-PRO shadow hard-coded credentials
63RIESGO
abrir
GitHub PoC
Divi Ajax Filter <= 5.1.2 Unauthenticated Local File Inclusion via 'custom_loop_template'
CVE-2026-11613CRITICAL04 sep 2026
Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
48RIESGO
abrir
GitHub PoC
CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port
CVE-2020-1938CRITICALbajo ataque04 sep 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
CVE-2026-19516
CVE-2026-19516CRITICAL04 sep 2026
CVE-2026-19516 CVE Record
48RIESGO
abrir
GitHub PoC
Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)
CVE-2026-19632CRITICAL04 sep 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RIESGO
abrir
GitHub PoC
Hunt-Benito/the-key-ships-with-the-lock-cve-2026-82876-phison-s11-ssd-firmware-signature-bypass
CVE-2026-82876CRITICAL04 sep 2026
Phison PS3111-S11 Controller Firmware Signature Verification Bypass
48RIESGO
abrir
GitHub PoC
CVE-2026-82329 Poc
CVE-2026-82329CRITICALbajo ataque04 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC
[MIRROR] The CVE-2026-85649 Security Research Publication.
CVE-2026-85649HIGH04 sep 2026
(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the A
41RIESGO
abrir
GitHub PoC
CVE-2026-77818 - Yordam Kütüphane Otomasyon Sistemi - Üç ayrı noktada yansıtılmış HTML enjeksiyonu, form action ele geçirme ve kimlik bilgisi hırsızlığı (CWE-79)
CVE-2026-77818MEDIUM04 sep 2026
Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System
33RIESGO
abrir
GitHub PoC
n0c71v3x/CVE-2026-78745
CVE-2026-78745CRITICAL04 sep 2026
An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via
48RIESGO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-10134
CVE-2026-10134CRITICAL04 sep 2026
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
48RIESGO
abrir
GitHub PoC
gustanini/CVE-2022-42889-Text4Shell-POC
CVE-2022-4288904 sep 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
dahnutz/zimbra-cve-2026-73570-ir
CVE-2026-73570HIGHbajo ataque04 sep 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC
CVE-2026-63077 - Unauthenticated RCE exploit for JetBrains TeamCity via Agent Polling Deserialization. Supports mass scanning, multi-threading, and interactive shell. For authorized security testing only.
CVE-2026-63077CRITICALbajo ataque04 sep 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RIESGO
abrir
GitHub PoC
Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769
CVE-2026-85769MEDIUM04 sep 2026
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize
33RIESGO
abrir
GitHub PoC
Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)
CVE-2026-83548CRITICALbajo ataque04 sep 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
78RIESGO
abrir
GitHub PoC
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
CVE-2026-85046HIGHbajo ataque04 sep 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir
GitHub PoC1
CVE-2026-85046
CVE-2026-85046HIGHbajo ataque04 sep 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-1094HIGH04 sep 2026
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.