Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.781exploits catalogados
36.771CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
GitHub PoC
cve-2026-19900-PoC
CVE-2026-19900CRITICAL04 sep 2026
LB-LINK X-PRO shadow hard-coded credentials
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-67303HIGH04 sep 2026
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a
56RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-34197HIGHbajo ataque04 sep 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
GitHub PoC
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
CVE-2026-85046HIGHbajo ataque04 sep 2026
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside
71RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque04 sep 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63077CRITICALbajo ataque04 sep 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RIESGO
abrir
GitHub PoC
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
CVE-2023-54391CRITICAL03 sep 2026
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
63RIESGO
abrir
Exploit-DB
FreePBX 17.0.2 - Remote Code Execution (RCE)
CVE-2025-57819CRITICALbajo ataquewebappsmultiple03 sep 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
CVE-2026-64788MEDIUM03 sep 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware03 sep 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
CVE-2026-80428 PoC
CVE-2026-80428CRITICAL03 sep 2026
ILIAS PHP Object Injection via Shibboleth Logout
48RIESGO
abrir
GitHub PoC
CVE-2026-19949 - Draft or TODO
CVE-2026-19949HIGH03 sep 2026
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
41RIESGO
abrir
GitHub PoC
CVE-2026-80428 PoC
CVE-2026-80428CRITICAL03 sep 2026
ILIAS PHP Object Injection via Shibboleth Logout
48RIESGO
abrir
GitHub PoC
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
CVE-2026-75604CRITICAL03 sep 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RIESGO
abrir
GitHub PoC2
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
CVE-2026-65643HIGH03 sep 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RIESGO
abrir
GitHub PoC
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343HIGH03 sep 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RIESGO
abrir
GitHub PoC
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
CVE-2026-56718HIGH03 sep 2026
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
41RIESGO
abrir
GitHub PoC
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
CVE-2026-82329CRITICALbajo ataque03 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
CVE-2026-83548CRITICALbajo ataque03 sep 2026
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
78RIESGO
abrir
GitHub PoC
PoC for CVE-2026-4813
CVE-2026-4813CRITICAL03 sep 2026
Code injection in the Lutece Core
48RIESGO
abrir
GitHub PoC
CVE-2026-59822 - Draft or TODO
CVE-2026-59822HIGHbajo ataque03 sep 2026
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
71RIESGO
abrir
GitHub PoC3
Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM exploit; for authorized testing
CVE-2026-62735HIGH03 sep 2026
Windows HTTP.sys Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-52810 - Draft or TODO
CVE-2026-52810HIGH03 sep 2026
Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion
41RIESGO
abrir
Exploit-DB
Metabase 0.61.0 - Authenticated Remote Code Execution
CVE-2026-59827CRITICALwebappsmultiple03 sep 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RIESGO
abrir
GitHub PoC
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
CVE-2026-78070MEDIUM03 sep 2026
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
33RIESGO
abrir
GitHub PoC1
CVE-2026-20212 - Draft or TODO
CVE-2026-20212CRITICAL03 sep 2026
Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC
Stored XSS via Location Title in DPCalendar Free
CVE-2026-78071HIGH03 sep 2026
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
41RIESGO
abrir
GitHub PoC1
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool
CVE-2017-5638CRITICALbajo ataqueransomware03 sep 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
ChrisBarack/cve-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware02 sep 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALbajo ataque02 sep 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
98RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.