Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
CVE-2026-43503HIGH29 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC3
Pure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration, integrated ELF parser.
CVE-2023-4911HIGHbajo ataque29 jun 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC1
React2Shell (CVE-2025-55182) PoC
CVE-2025-55182CRITICALbajo ataqueransomware29 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC1
CVE-2026-46817
CVE-2026-46817CRITICALbajo ataque29 jun 2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
83RIESGO
abrir
GitHub PoC
POC for CVE-2026-20253
CVE-2026-20253CRITICALbajo ataque29 jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RIESGO
abrir
GitHub PoC1
CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.
CVE-2026-56782CRITICAL29 jun 2026
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RIESGO
abrir
GitHub PoC1
iCagenda Unauthenticated File Upload to RCE
CVE-2026-48939CRITICALbajo ataque29 jun 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
100RIESGO
abrir
GitHub PoC
rufflabs/ludus_crushftp_cve-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware29 jun 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
rufflabs/ludus_crushftp_cve-2025-31161_sim
CVE-2025-31161CRITICALbajo ataqueransomware29 jun 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
HutTwoThreeFour/CVE-2026-5562-Exploit
CVE-2026-5562MEDIUM29 jun 2026
provectus kafka-ui Endpoint testexecutions validateAccess code injection
33RIESGO
abrir
GitHub PoC1
rootdirective-sec/CVE-2026-28496-Lab
CVE-2026-28496CRITICAL29 jun 2026
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
68RIESGO
abrir
GitHub PoC
drupal-postgresql-rce
CVE-2026-9082CRITICALbajo ataque29 jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RIESGO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHbajo ataqueransomware29 jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHbajo ataqueransomware29 jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2021-26855CRITICALbajo ataqueransomware29 jun 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC2
CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)
CVE-2026-48907CRITICALbajo ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC25
Python Proof of Concept for DirtyClone (CVE-2026-43503) - Linux kernel LPE via page-cache corruption
CVE-2026-43503HIGH29 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC4
CVE-2026-55200 - Critical libssh2 Remote Code Execution Vulnerability
CVE-2026-55200CRITICAL29 jun 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2021-26855CRITICALbajo ataqueransomware29 jun 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC
cve-2026-48907 scanner
CVE-2026-48907CRITICALbajo ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
xitexploiter96-dot/CVE-2026-48907-
CVE-2026-48907CRITICALbajo ataque29 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
cve-2026-46331-audit script
CVE-2026-46331HIGH29 jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC
CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.
CVE-2026-53753CRITICAL29 jun 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RIESGO
abrir
GitHub PoC
Goal is to triage well known attack and learn how security teams quickly respond.
CVE-2021-44228CRITICALbajo ataqueransomware28 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
React2Shell: CVE-2025-55182 exploit from tryhackme‼️
CVE-2025-55182CRITICALbajo ataqueransomware28 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
CVE-2026-48908CRITICAL28 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
85RIESGO
abrir
GitHub PoC
Goal is to triage well known attack and learn how security teams quickly respond.
CVE-2021-44228CRITICALbajo ataqueransomware28 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
solmin111/OpenSMTPD-CVE-2020-7247-
CVE-2020-7247CRITICALbajo ataque28 jun 2026
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC1
CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)
CVE-2026-49048HIGH28 jun 2026
Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1
41RIESGO
abrir
GitHub PoC1
CVE-2026-12485
CVE-2026-12485CRITICAL28 jun 2026
GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.