Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
initial-access
CVE-2026-16723CRITICAL20 jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RIESGO
abrir
GitHub PoC4
WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
joaovicdev/EXPLOIT-CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Docker ortamında Apache HTTP Server 2.4.49 (CVE-2021-42013) zafiyetinin gösterildiği laboratuvar çalışması.
CVE-2021-42013CRITICALbajo ataqueransomware20 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Dungsocool/CVE-2024-23897
CVE-2024-23897CRITICALbajo ataqueransomware20 jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue operations with the endpoint's service-account credentials (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48206MEDIUM20 jul 2026
Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials
33RIESGO
abrir
GitHub PoC2
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
CVE-2026-63030CRITICALbajo ataque20 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla
CVE-2026-48907CRITICALbajo ataque19 jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
The wp2shell vulnerability chain represents one of the most significant WordPress Core security issues in recent years. Because exploitation begins with an unauthenticated request and can ultimately result in Remote Code Execution, organizations should treat remediation as an emergency.
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
Exploit POC for Wp2Shell, CVE-2026-63030 + CVE-2026-63137
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC3
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC2
CVE-2026-63030 / wp2shell
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC10
wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
sadsadsa
CVE-2026-66804HIGH19 jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-56290CRITICAL19 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir
GitHub PoC5
Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
0xh7ml/CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC8
CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack detection, automated firewall response, configuration auditing, and security reporting for legacy and unsupported systems.
CVE-2017-0144HIGHbajo ataqueransomware19 jul 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque19 jul 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC5
CVE-2026-46215 DRM GEM UAF Exploit for Linux 7.0 - The first working PoC for linux kernel 7 use after free- by Antonius (sw0rdm4n, w1sdom, ev1lut10n)
CVE-2026-46215HIGH19 jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RIESGO
abrir
GitHub PoC2
CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated testing. Validates critical RCE vulnerability impact. For authorized security assessments only.
CVE-2026-33017CRITICALbajo ataque19 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
TomorrowX6/CVE-2026-63030-poc
CVE-2026-63030CRITICALbajo ataque19 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque19 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMbajo ataque19 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
anteriorpágina 55 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.