Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC4
Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler
CVE-2026-49049HIGH04 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
61RIESGO
abrir
GitHub PoC
💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell
CVE-2026-57517CRITICAL04 jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RIESGO
abrir
GitHub PoC30
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC3
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
CVE-2026-56290CRITICAL04 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
85RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-53360: guest-triggered heap out-of-bounds read/write in KVM SEV-SNP Page State Change (PSC) handling.
CVE-2026-53360HIGH04 jul 2026
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
21RIESGO
abrir
GitHub PoC1
caterscam/CVE-2026-5524-PoC
CVE-2026-5524CRITICAL04 jul 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
28RIESGO
abrir
GitHub PoC
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
CVE-2026-23869HIGH04 jul 2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
41RIESGO
abrir
GitHub PoC5
Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison
CVE-2026-34197HIGHbajo ataque04 jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
GitHub PoC
Casdoor version 2.362.0
CVE-2026-9090CRITICAL04 jul 2026
CVE-2026-9090
48RIESGO
abrir
GitHub PoC
CVE-2026-59243 — Apache Airflow FAB Auth Manager JWT signature bypass (embargoed until Apache advisory)
CVE-2026-59243CRITICAL04 jul 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RIESGO
abrir
GitHub PoC
Unauthenticated RCE in Langflow <1.9.0 (CVE-2026-33017) Exploit
CVE-2026-33017CRITICALbajo ataque04 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC2
PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover
CVE-2026-54415HIGH04 jul 2026
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
21RIESGO
abrir
GitHub PoC
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
CVE-2026-23744CRITICAL04 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
Script de python para Webmin 1.996
CVE-2022-3644604 jul 2026
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
GitHub PoC
PoC of Langflow CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque04 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 jul 2026
NGINX Map directive and Regex matching vulnerability
48RIESGO
abrir
GitHub PoC3
CVE-2026-54998 RCE Exploit
CVE-2026-54998HIGH04 jul 2026
Microsoft Exchange Online Elevation of Privilege Vulnerability
21RIESGO
abrir
GitHub PoC
kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup
CVE-2011-252303 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC4
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
CVE-2026-28995HIGH03 jul 2026
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
41RIESGO
abrir
GitHub PoC1
CVE-2026-8451
CVE-2026-8451HIGH03 jul 2026
Insufficient input validation leading to memory overread
46RIESGO
abrir
GitHub PoC
CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.
CVE-2026-49468CRITICAL03 jul 2026
LiteLLM: Authentication Bypass via Host Header Injection
28RIESGO
abrir
GitHub PoC5
☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE
CVE-2026-44825HIGH03 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RIESGO
abrir
GitHub PoC
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore.
CVE-2026-53753CRITICAL03 jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RIESGO
abrir
GitHub PoC
Pardus Software Local Privilege Escalation PoC - affected from <= 1.0.4
CVE-2026-14459HIGH03 jul 2026
Argument Injection in TUBITAK BILGEM's pardus-software
21RIESGO
abrir
GitHub PoC1
1beelze/CVE-2026-11387
CVE-2026-11387CRITICAL03 jul 2026
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
28RIESGO
abrir
GitHub PoC2
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter
CVE-2026-56290CRITICAL03 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
85RIESGO
abrir
GitHub PoC
Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape
CVE-2026-53362HIGH03 jul 2026
ipv6: account for fraggap on the paged allocation path
41RIESGO
abrir
GitHub PoC
CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)
CVE-2017-12615HIGHbajo ataqueransomware03 jul 2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC1
Proof of concept for CVE-2026-36027 and CVE-2026-36028
CVE-2026-36027MEDIUM02 jul 2026
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via
13RIESGO
abrir
GitHub PoC
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
CVE-2026-13768CRITICAL02 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.