Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.842exploits catalogados
36.821CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
Exploit-DB
EVerest 2025.9.0 - DoS
CVE-2025-68137HIGHdosmultiple02 sep 2026
EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
41RIESGO
abrir
GitHub PoC1
Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).
CVE-2011-252302 sep 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
rmhowe425/POC-CVE-2026-5027
CVE-2026-5027HIGH02 sep 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL02 sep 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque02 sep 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC5
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 sep 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RIESGO
abrir
GitHub PoC10
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 sep 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RIESGO
abrir
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHbajo ataque02 sep 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 sep 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RIESGO
abrir
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 sep 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RIESGO
abrir
GitHub PoC
tcollins-hashicorp/vault-cve-2026-5006-audit
CVE-2026-5006MEDIUM02 sep 2026
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
33RIESGO
abrir
GitHub PoC6
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC1
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALbajo ataqueransomware02 sep 2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-5027HIGH02 sep 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-2907802 sep 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14667CRITICALbajo ataque02 sep 2026
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL02 sep 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL02 sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALbajo ataque02 sep 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
98RIESGO
abrir
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 sep 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RIESGO
abrir
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 sep 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RIESGO
abrir
GitHub PoC
Saku0512/CVE-2026-84361-poc
CVE-2026-84361HIGH02 sep 2026
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24423CRITICALbajo ataqueransomware02 sep 2026
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
100RIESGO
abrir
GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
CVE-2026-9335MEDIUM02 sep 2026
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RIESGO
abrir
GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828/CVE-2026-72243 PoC)
CVE-2026-63828HIGH02 sep 2026
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RIESGO
abrir
GitHub PoC
nabeelmkhan/CVE-2026-78839
CVE-2026-7883902 sep 2026
An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.