Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC★ 23
基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RIESGO
abrir ↗GitHub PoC
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
33RIESGO
abrir ↗GitHub PoC★ 27
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC★ 17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 41
CVE-2026-50522 PoC
Microsoft SharePoint Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RIESGO
abrir ↗GitHub PoC
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
33RIESGO
abrir ↗GitHub PoC★ 1
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RIESGO
abrir ↗GitHub PoC★ 2
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RIESGO
abrir ↗GitHub PoC
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
33RIESGO
abrir ↗GitHub PoC
Auth Bypass in inetutils-telnetd
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RIESGO
abrir ↗GitHub PoC
Manage BitLocker encrypted drives on Windows 10 and 11. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
Windows BitLocker Security Feature Bypass Vulnerability
33RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-54121
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir ↗GitHub PoC
Security Advisory for CVE-2026-51565
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker
33RIESGO
abrir ↗GitHub PoC
CVE-2026-54121 - Draft
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗VulnCheck XDB
local
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RIESGO
abrir ↗VulnCheck XDB
initial-access
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗GitHub PoC★ 1
CypherHippie/CVE-2026-66804
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir ↗GitHub PoC★ 3
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC
Security Advisory for CVE-2026-51564
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RIESGO
abrir ↗GitHub PoC
EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RIESGO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.