Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.329exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 ago 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RIESGO
abrir
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
CVE-2026-73519CRITICAL16 ago 2026
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RIESGO
abrir
GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
CVE-2026-71206HIGH16 ago 2026
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RIESGO
abrir
GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
CVE-2026-71205MEDIUM16 ago 2026
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RIESGO
abrir
GitHub PoC3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
CVE-2026-6837HIGH16 ago 2026
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RIESGO
abrir
GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
CVE-2026-8508MEDIUM16 ago 2026
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RIESGO
abrir
GitHub PoC
CVE-2026-73633(S2-072)概念验证代码
CVE-2026-73633HIGH16 ago 2026
Apache Struts: Unbounded read of a JSON request body
41RIESGO
abrir
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 ago 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RIESGO
abrir
GitHub PoC3
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
CVE-2026-43499HIGH16 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 ago 2026
23RIESGO
abrir
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 ago 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RIESGO
abrir
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 ago 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-72898
CVE-2026-72898CRITICALbajo ataque15 ago 2026
Metabase SQL injection via password reset endpoint
98RIESGO
abrir
GitHub PoC
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
CVE-2026-20896CRITICAL15 ago 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
75RIESGO
abrir
GitHub PoC
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True
CVE-2026-47117CRITICAL15 ago 2026
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
48RIESGO
abrir
GitHub PoC2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
CVE-2026-43499HIGH15 ago 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.
CVE-2026-9090CRITICAL15 ago 2026
CVE-2026-9090
48RIESGO
abrir
GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
CVE-2024-4577CRITICALbajo ataqueransomware15 ago 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
CVE-2026-47103CRITICAL15 ago 2026
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RIESGO
abrir
GitHub PoC2
SambaCry Explanation and Exploitation Demo
CVE-2017-7494CRITICALbajo ataqueransomware15 ago 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 ago 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RIESGO
abrir
GitHub PoC254
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 ago 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RIESGO
abrir
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 ago 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RIESGO
abrir
GitHub PoC
esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
CVE-2026-8793MEDIUM15 ago 2026
PaperCut NG/MF: Insufficient brute-force protection
33RIESGO
abrir
GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
CVE-2026-8794MEDIUM15 ago 2026
PaperCut NG/MF: User enumeration via timing attack
33RIESGO
abrir
GitHub PoC
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.
CVE-2026-64638HIGH15 ago 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
56RIESGO
abrir
GitHub PoC1
CVE-2026-72898-Metabase-SQLi-Fix
CVE-2026-72898CRITICALbajo ataque15 ago 2026
Metabase SQL injection via password reset endpoint
98RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.