Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC1
Gitea diffpatch RCE
CVE-2026-60004CRITICALbajo ataque30 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC4
CVE-2026-60004
CVE-2026-60004CRITICALbajo ataque29 jul 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36104CRITICAL29 jul 2026
Apache OFBiz: Path traversal leading to a RCE
85RIESGO
abrir
GitHub PoC5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
CVE-2026-58025MEDIUM29 jul 2026
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-50522-Proof-of-Concept
CVE-2026-50522CRITICALbajo ataque29 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-57811-Proof-of-Concept
CVE-2026-57811CRITICAL29 jul 2026
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
manfredgabriel/cve-2021-41773-lab
CVE-2021-41773HIGHbajo ataqueransomware29 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Pravin761/CVE-2026-54107
CVE-2026-54107HIGH29 jul 2026
Windows Win32k Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
webshellseo8/CVE-2026-61511-POC
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RIESGO
abrir
GitHub PoC
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
CVE-2026-64531HIGH29 jul 2026
net: openvswitch: reject oversized nested action attrs
41RIESGO
abrir
GitHub PoC2
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-45746CRITICAL29 jul 2026
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RIESGO
abrir
GitHub PoC5
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVE-2026-49176HIGH29 jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC1
Gitea Docker Image Authentication Bypass
CVE-2026-20896CRITICAL29 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RIESGO
abrir
GitHub PoC
Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so ../../../../tmp/x.txt:handler escapes the build tempdir via path.Join, letting an attacker write arbitrary content to any path as root. (CVE-2026-52832, ≤1.15.27)
CVE-2026-52832MEDIUM29 jul 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container
33RIESGO
abrir
GitHub PoC
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir
GitHub PoC23
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir
GitHub PoC
CVE-2026-2586 — Eclipse GlassFish EL injection to RCE
CVE-2026-2586CRITICAL29 jul 2026
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RIESGO
abrir
GitHub PoC15
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
CVE-2026-57827CRITICAL29 jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-41773HIGHbajo ataqueransomware29 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2025-24293CRITICAL29 jul 2026
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
63RIESGO
abrir
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir
GitHub PoC1
CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)
CVE-2026-43499HIGH29 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RIESGO
abrir
GitHub PoC5
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full toolkit: reverse shell, proxy, persistence, webshell, database operations, firewall control, log management, mass scanning. 2 versions: multi-exploit & safe-check. Python 3.8+ Use Ethically, Stay Legal. 🔒
CVE-2026-61511CRITICAL29 jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RIESGO
abrir
GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
CVE-2026-52134CRITICAL29 jul 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RIESGO
abrir
GitHub PoC
CamilleGR/CVE-2026-73292
CVE-2026-73292HIGH29 jul 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
41RIESGO
abrir
GitHub PoC9
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
CVE-2026-43813HIGH29 jul 2026
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
41RIESGO
abrir
GitHub PoC
Reproducible SOC lab for CVE-2024-4577 detection and response
CVE-2024-4577CRITICALbajo ataqueransomware29 jul 2026
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC1
CVE-2026-66066
CVE-2026-66066CRITICAL29 jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RIESGO
abrir
anteriorpágina 43 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.