Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque27 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-9830HIGH27 jul 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RIESGO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC1
soralis0912/CVE-2026-43499-warhol-root
CVE-2026-43499HIGH26 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC3
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.
CVE-2026-41940CRITICALbajo ataqueransomware26 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
CVE-2026-66754HIGH26 jul 2026
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware26 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALbajo ataqueransomware26 jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
GitHub PoC1
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
CVE-2026-67184HIGH26 jul 2026
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
41RIESGO
abrir
GitHub PoC6
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
CVE-2026-64600HIGH26 jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RIESGO
abrir
GitHub PoC
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
CVE-2026-66746MEDIUM26 jul 2026
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RIESGO
abrir
GitHub PoC
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
CVE-2026-66749HIGH26 jul 2026
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RIESGO
abrir
GitHub PoC3
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
CVE-2026-10818HIGH26 jul 2026
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
41RIESGO
abrir
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
CVE-2026-66751MEDIUM26 jul 2026
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RIESGO
abrir
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
CVE-2026-66750MEDIUM26 jul 2026
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RIESGO
abrir
GitHub PoC
Adding --insecure to skip ssl
CVE-2026-60137MEDIUMbajo ataque26 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
CVE-2026-67182MEDIUM26 jul 2026
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RIESGO
abrir
GitHub PoC
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
CVE-2026-67183HIGH26 jul 2026
TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
41RIESGO
abrir
GitHub PoC1
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
CVE-2026-67185HIGH26 jul 2026
TinyWeb 0.0.8 Path Traversal via URL Path Component
41RIESGO
abrir
GitHub PoC4
CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)
CVE-2026-43499HIGH26 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
CVE-2026-66753MEDIUM26 jul 2026
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque26 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
CVE-2026-54121HIGH26 jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.
CVE-2021-44228CRITICALbajo ataqueransomware26 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-15981CRITICAL26 jul 2026
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RIESGO
abrir
GitHub PoC3
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.
CVE-2026-58480CRITICAL26 jul 2026
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RIESGO
abrir
GitHub PoC
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
CVE-2026-15981CRITICAL26 jul 2026
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RIESGO
abrir
GitHub PoC
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
CVE-2026-66752MEDIUM26 jul 2026
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
33RIESGO
abrir
GitHub PoC2
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE, in-process machine key theft, and the artifacts each variant leaves behind. SharePoint 2016, 2019, and Subscription Edition. CVE-2026-50522, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644.
CVE-2026-50522CRITICALbajo ataque26 jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization
CVE-2026-66012CRITICAL26 jul 2026
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
48RIESGO
abrir
anteriorpágina 46 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.