Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)
CVE-2026-48598LOW09 jun 2026
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
28RIESGO
abrir
GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
CVE-2026-45247CRITICALbajo ataque09 jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2025-11262-Lab
CVE-2025-11262HIGH09 jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RIESGO
abrir
GitHub PoC
Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528
CVE-2025-59528CRITICAL09 jun 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
GitHub PoC
kennedy-aikohi/mcpjam-cve-2026-23744-validator
CVE-2026-23744CRITICAL09 jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-23479
CVE-2026-23479HIGH09 jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-33829
CVE-2026-33829MEDIUM09 jun 2026
Windows Snipping Tool Spoofing Vulnerability
33RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2024-21182
CVE-2024-21182HIGHbajo ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RIESGO
abrir
GitHub PoC1
I created simple react2shell CVE-2025-55182 python exploit
CVE-2025-55182CRITICALbajo ataqueransomware09 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-42945
CVE-2026-42945CRITICAL09 jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
dotCMS Pre-auth SQL Injection
CVE-2026-8054CRITICAL09 jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-28318
CVE-2026-28318HIGHbajo ataque09 jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
71RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-48595
CVE-2026-48595HIGH09 jun 2026
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-45659
CVE-2026-45659HIGHbajo ataqueransomware09 jun 2026
Microsoft SharePoint Remote Code Execution Vulnerability
71RIESGO
abrir
GitHub PoC
fevar54/CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE
CVE-2024-21182HIGHbajo ataque09 jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-35616
CVE-2026-35616CRITICALbajo ataque09 jun 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir
GitHub PoC
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de hardening
CVE-2024-42327CRITICAL09 jun 2026
SQL injection in user.get API
70RIESGO
abrir
GitHub PoC1
Insert PHP Plugin PHP Code Injection
CVE-2017-20251CRITICAL09 jun 2026
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
48RIESGO
abrir
GitHub PoC
CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)
CVE-2021-44228CRITICALbajo ataqueransomware09 jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
v3s9er/CVE-2026-52885
CVE-2026-52885HIGH09 jun 2026
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
41RIESGO
abrir
GitHub PoC
CVE-2026-45067 - Draft
CVE-2026-45067MEDIUM09 jun 2026
Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
33RIESGO
abrir
GitHub PoC
jenniferreire26/CVE-2026-0257
CVE-2026-0257HIGHbajo ataqueransomware09 jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
CVE-2026-46394HIGH09 jun 2026
HAX CMS Vulnerable to Command Injection using Git.php
41RIESGO
abrir
GitHub PoC
CVE-2024-52011 - Draft
CVE-2024-52011HIGH09 jun 2026
launch-editor vulnerable to command injection via the crafted request on Windows
41RIESGO
abrir
GitHub PoC1
VE-2025-48595 es una vulnerabilidad de **desbordamiento de entero (integer overflow)** en múltiples ubicaciones del Framework de Android.
CVE-2025-48595HIGHbajo ataque09 jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RIESGO
abrir
GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
CVE-2026-47429CRITICAL09 jun 2026
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RIESGO
abrir
GitHub PoC
willygailo/WG-CVE-2026-1555-Linux
CVE-2026-1555CRITICAL08 jun 2026
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
GitHub PoC1
Mitigation scripts for CVE-2026-50751
CVE-2026-50751CRITICALbajo ataqueransomware08 jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
GitHub PoC
Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility
CVE-2025-32433CRITICALbajo ataque08 jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RIESGO
abrir
GitHub PoC
Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.
CVE-2018-1676308 jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.