Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Proof-of-concept exploit and lab environment for CVE-2026-25194
CVE-2026-25194LOW02 jul 2026
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve
8RIESGO
abrir
GitHub PoC
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
CVE-2026-13768CRITICAL02 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RIESGO
abrir
GitHub PoC
CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)
CVE-2026-55726MEDIUM02 jul 2026
Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
13RIESGO
abrir
GitHub PoC
DESIGN AND IMPLEMENTATION OF A VULNERABILITY SCANNER FOR CVE-2026-45498 IN MICROSOFT DEFENDER
CVE-2026-45498MEDIUMbajo ataque02 jul 2026
Microsoft Defender Denial of Service Vulnerability
55RIESGO
abrir
GitHub PoC
kaleth4/CVE-2026-55200
CVE-2026-55200CRITICAL02 jul 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir
GitHub PoC1
kaleth4/CVE-2026-20896
CVE-2026-20896CRITICAL02 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
75RIESGO
abrir
GitHub PoC2
dinosn/CVE-2026-25243-debugfree
CVE-2026-25243HIGH02 jul 2026
redis-server RESTORE invalid memory access may allow remote code execution
41RIESGO
abrir
GitHub PoC
CVE-2025-5777 Research writeup
CVE-2025-5777CRITICALbajo ataqueransomware02 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Crawl4AI <= 0.8.6 pre-auth RCE via AST sandbox escape (gi_frame.f_back.f_builtins chain) — CVSS 10.0
CVE-2026-53753CRITICAL02 jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RIESGO
abrir
GitHub PoC2
Python POC, Exploit for CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque02 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC1
FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168
CVE-2026-12166MEDIUM02 jul 2026
CVE-2026-12166
13RIESGO
abrir
GitHub PoC
Hunt-Benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection
CVE-2026-58116CRITICAL02 jul 2026
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
48RIESGO
abrir
GitHub PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functionality, leading to arbitrary file upload and remote code execution (RCE).
CVE-2026-38751HIGH02 jul 2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RIESGO
abrir
GitHub PoC
attarwahyup/Netscaler-CVE-2026-8451
CVE-2026-8451HIGH02 jul 2026
Insufficient input validation leading to memory overread
46RIESGO
abrir
GitHub PoC
Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /api/dump and /api/restore endpoints, letting unauthenticated remote attackers access and modify protected data, exploit requires default empty admin_api_key configuration.
CVE-2026-56782CRITICAL02 jul 2026
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RIESGO
abrir
GitHub PoC8
SimpleHelp OIDC Authentication Bypass PoC
CVE-2026-48558CRITICAL02 jul 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
53RIESGO
abrir
GitHub PoC
CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)
CVE-2026-54477MEDIUM02 jul 2026
Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
13RIESGO
abrir
GitHub PoC
BastianXploited/CVE-2026-0740-mass
CVE-2026-0740CRITICAL02 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC
do4choo/CVE-2026-53694-NoMachine-LPE
CVE-2026-53694HIGH01 jul 2026
Potential local privileges escalation through argument injection in the nxchmod.sh script
21RIESGO
abrir
GitHub PoC
Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy
CVE-2025-24054MEDIUMbajo ataque01 jul 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
Safari 跨域信息读取
CVE-2026-43735HIGH01 jul 2026
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS
21RIESGO
abrir
GitHub PoC1
OpenSTAManager RCE Exploit (CVE-2026-38751)
CVE-2026-38751HIGH01 jul 2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RIESGO
abrir
GitHub PoC8
CVE-2026-6307 PoC: Longinus - 2 Boundaries in One Bug https://nebusec.ai/research/v8-cve-2026-6307-writeup/)
CVE-2026-6307HIGH01 jul 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code
41RIESGO
abrir
GitHub PoC48
Google Chrome CVE-2026-6307 PoC
CVE-2026-6307HIGH01 jul 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code
41RIESGO
abrir
GitHub PoC
CVE-2026-48907 PoC
CVE-2026-48907CRITICALbajo ataque01 jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
CyberDefenders JetBrains Lab
CVE-2024-27198CRITICALbajo ataqueransomware01 jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RIESGO
abrir
GitHub PoC1
🛡️ CVE Proof-of-Concept Hub — 21 security advisories · 80+ vulnerabilities · 19 CVEs under review · 1 PUBLISHED (CVE-2026-66412)
CVE-2026-66412HIGH01 jul 2026
Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC
21RIESGO
abrir
GitHub PoC
O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma vulnerabilidade crítica no TMUI que, em versões não corrigidas, pode permitir acesso não autorizado e execução remota de código, reforçando a necessidade de atualização e gestão contínua de vulnerabilidades.
CVE-2020-5902CRITICALbajo ataqueransomware01 jul 2026
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-56011-Lab
CVE-2026-56011HIGH01 jul 2026
WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability
21RIESGO
abrir
GitHub PoC
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
CVE-2026-55488HIGH01 jul 2026
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
21RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.