Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
CVE-2025-32432CRITICALbajo ataque05 ago 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC13
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430MEDIUM05 ago 2026
CVE-2026-15430
33RIESGO
abrir
GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
CVE-2026-58062CRITICAL05 ago 2026
Stapled OCSP response accepted without binding to the checked certificate
48RIESGO
abrir
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALbajo ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
CVE-2026-43284HIGH05 ago 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
minwunn/wp2shell-CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 ago 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RIESGO
abrir
GitHub PoC
CVE-2026-71211 exploit
CVE-2026-71211HIGH05 ago 2026
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RIESGO
abrir
GitHub PoC1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-26190CRITICAL05 ago 2026
Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
75RIESGO
abrir
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 ago 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RIESGO
abrir
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 ago 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RIESGO
abrir
GitHub PoC
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.
CVE-2026-54917HIGH05 ago 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
56RIESGO
abrir
GitHub PoC917
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque05 ago 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque05 ago 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
lucastran05/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware05 ago 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2023-6553
CVE-2023-6553CRITICAL05 ago 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque05 ago 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque05 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque05 ago 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMbajo ataque05 ago 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-38831HIGHbajo ataqueransomware05 ago 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque05 ago 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
0xdak/CVE-2026-44024_exploit
CVE-2026-44024CRITICAL05 ago 2026
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL05 ago 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL05 ago 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque05 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 ago 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RIESGO
abrir
GitHub PoC
George0Papasotiriou/CVE-2026-11112-XXE-via-SVG-Image-Upload
CVE-2026-11112CRITICAL04 ago 2026
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remo
48RIESGO
abrir
anteriorpágina 34 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.