Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC10
CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker
CVE-2026-20896CRITICAL07 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
75RIESGO
abrir
GitHub PoC1
A complete walkthrough and exploit for CVE-2019-9978 - Unauthenticated Remote Code Execution in Social Warfare WordPress plugin ≤ 3.5.2. Includes vulnerable code analysis and payload examples.
CVE-2019-9978MEDIUMbajo ataque07 jul 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC1
Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component
CVE-2026-36214MEDIUM07 jul 2026
osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable
13RIESGO
abrir
GitHub PoC
Bypass Authentication
CVE-2026-48611CRITICAL07 jul 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
GitHub PoC
CVE-2021-3156 (Baron Samedit) Report and Research
CVE-2021-3156HIGHbajo ataque07 jul 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Shellshock
CVE-2014-6271CRITICALbajo ataque07 jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
CVE-2026-11405 - Draft
CVE-2026-11405CRITICAL07 jul 2026
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
28RIESGO
abrir
GitHub PoC
Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE
CVE-2026-12277HIGH07 jul 2026
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal
41RIESGO
abrir
GitHub PoC
NEO-SQLi — exploit Django _connector SQL Injection (CVE-2025-64459) | canal RedTeam Brasil
CVE-2025-64459CRITICAL07 jul 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir
GitHub PoC
CVE-2026-14191 - Draft
CVE-2026-14191HIGH07 jul 2026
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
21RIESGO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS, covering arbitrary CFM file write, code execution as the ColdFusion service user, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48282CRITICAL07 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
85RIESGO
abrir
GitHub PoC2
CVE-2026-8451 - Citrix NetScaler SAML Memory Overread (CitrixBleed) - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-8451HIGH07 jul 2026
Insufficient input validation leading to memory overread
46RIESGO
abrir
GitHub PoC
PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.
CVE-2026-54350CRITICAL07 jul 2026
Budibase: Anonymous NoSQL operator injection via published-app query templates
28RIESGO
abrir
GitHub PoC1
CVE-2026-39492 — WP Maps (wp-google-map-plugin) <= 4.9.1 Unauthenticated Blind SQL Injection Mass Scanner | sqlmap-style detection | backtick bypass esc_sql() | 100K+ installs
CVE-2026-39492CRITICAL07 jul 2026
WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability
28RIESGO
abrir
GitHub PoC60
CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH
CVE-2026-42980HIGH07 jul 2026
NT OS Kernel Elevation of Privilege Vulnerability
21RIESGO
abrir
GitHub PoC
🐳 docker-compose 를 활용한 취약한 환경 구성 및 검증 (vulhub 한글판)
CVE-2026-40519HIGH07 jul 2026
Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
21RIESGO
abrir
GitHub PoC1
CVE-2026-45659 - Microsoft SharePoint Deserialization RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-45659HIGHbajo ataqueransomware07 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
71RIESGO
abrir
GitHub PoC3
CVE-2026-42271 - LiteLLM AI Gateway MCP Command Injection RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-42271HIGHbajo ataque07 jul 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RIESGO
abrir
GitHub PoC
CVE-2026-53359 - Draft
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC1
A17-ba/CVE-2026-51119
CVE-2026-51119CRITICAL07 jul 2026
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co
28RIESGO
abrir
GitHub PoC4
CVE-2026-53359
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC
This is a Proof-of-Concept for the Blink CSS UAF vulnerability tracked as CVE-2026-6300.
CVE-2026-6300HIGH07 jul 2026
Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid
41RIESGO
abrir
GitHub PoC
Vtiger CRM 8.3.0, 8.4.0 Module Import Authenticated RCE PoC
CVE-2026-23698HIGH07 jul 2026
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
41RIESGO
abrir
GitHub PoC7
jaf0rk/CVE-2026-14382
CVE-2026-14382CRITICAL06 jul 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
28RIESGO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
CVE-2026-49352CRITICAL06 jul 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
28RIESGO
abrir
GitHub PoC
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC1
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution
CVE-2024-39024HIGH06 jul 2026
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
41RIESGO
abrir
GitHub PoC
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware06 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-24061-PoC
CVE-2026-24061CRITICALbajo ataque06 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.