Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)
CVE-2026-40048HIGH08 jul 2026
Apache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
41RIESGO
abrir
GitHub PoC
Exploit for CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware08 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
CVE-2026-40453CRITICAL08 jul 2026
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
48RIESGO
abrir
GitHub PoC7
CVE-2026-43499
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-43499 - Draft
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC
junghyeonkum/CVE-2022-24706
CVE-2022-24706CRITICALbajo ataque08 jul 2026
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
GitHub PoC1
CVE-2026-8206 - Kirki WordPress Plugin Unauthenticated Account Takeover - PoC & Analysis | CVSS 9.8 CRITICAL | AMN SECURITY
CVE-2026-8206CRITICAL08 jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RIESGO
abrir
GitHub PoC1
Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy
CVE-2026-43284HIGH08 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
CVE-2026-53359HIGH08 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC4
CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploader.
CVE-2026-56290CRITICAL08 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
85RIESGO
abrir
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC2
Verificador de Vulnerabilidad: Bad Epoll (CVE-2026-46242)
CVE-2026-46242HIGH08 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
21RIESGO
abrir
GitHub PoC12
Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.
CVE-2026-44825HIGH08 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RIESGO
abrir
GitHub PoC1
CVE-2026-0257 - Palo Alto PAN-OS GlobalProtect Auth Override Cookie Forgery - PoC & Analysis | CVSS 9.1 CRITICAL CISA KEV | AMN SECURITY
CVE-2026-0257HIGHbajo ataqueransomware08 jul 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
GitHub PoC
Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape
CVE-2026-46316CRITICAL08 jul 2026
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
48RIESGO
abrir
GitHub PoC
eunho87/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware08 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
CVE-2026-49777 - WooCommerce Product Slider Pro Malicious Software Implantation RCE - PoC & Analysis | CVSS 10.0 CRITICAL | AMN SECURITY
CVE-2026-49777CRITICAL08 jul 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RIESGO
abrir
GitHub PoC16
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
CVE-2026-57239HIGH08 jul 2026
Foxit PDF Editor/Reader Local Privilege Escalation
41RIESGO
abrir
GitHub PoC
zero-trace7/CVE-2026-50229
CVE-2026-50229MEDIUM08 jul 2026
Apache Tomcat: XSS in number guess example
28RIESGO
abrir
GitHub PoC2
Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal
CVE-2026-40047CRITICAL08 jul 2026
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
28RIESGO
abrir
GitHub PoC
CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC
CVE-2026-33017CRITICALbajo ataque08 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
NEO-SQLi — exploit Django _connector SQL Injection (CVE-2025-64459) | canal RedTeam Brasil
CVE-2025-64459CRITICAL07 jul 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC3
CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For authorized security testing only.
CVE-2026-48908CRITICAL07 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir
GitHub PoC2
Linux 内核升级指南 - 修复 CVE-2026-53359
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC5
Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — covers every operational scenario. / KVM/x86 shadow MMU 虚拟机逃逸漏洞(CVE-2026-53359)的完整修复方案集合。 从零停机热修复到内核升级,覆盖所有运维场景。
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC2
IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE (CVE-2026-43284/43500). CC0.
CVE-2026-43284HIGH07 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS, covering arbitrary CFM file write, code execution as the ColdFusion service user, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48282CRITICAL07 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
85RIESGO
abrir
GitHub PoC
Vtiger CRM 8.3.0 Authenticated RCE via .phar Upload
CVE-2026-23697HIGH07 jul 2026
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
41RIESGO
abrir
GitHub PoC
This is a Proof-of-Concept for the Blink CSS UAF vulnerability tracked as CVE-2026-6300.
CVE-2026-6300HIGH07 jul 2026
Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.