Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.846exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8932Nuclei 4383Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.697 exploits
GitHub PoC★ 72
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RIESGO
abrir ↗GitHub PoC★ 2
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RIESGO
abrir ↗GitHub PoC
byt3l0rd/CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir ↗GitHub PoC
CVE-2026-73296
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RIESGO
abrir ↗Exploit-DB
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
Bludit CMS Reflected XSS via Search Plugin
33RIESGO
abrir ↗VulnCheck XDB
initial-access
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir ↗GitHub PoC
Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗GitHub PoC★ 1
Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB
Marimo 0.20.4 - RCE
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗GitHub PoC★ 5
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RIESGO
abrir ↗GitHub PoC★ 10
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RIESGO
abrir ↗GitHub PoC
SAP-system-update/CVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RIESGO
abrir ↗Exploit-DB
miniOrange 5.4.3 - Unauthenticated Auth Bypass
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RIESGO
abrir ↗GitHub PoC★ 1
Ghxstsec/CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir ↗GitHub PoC
pervinzahidli/CVE-2026-75855
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RIESGO
abrir ↗Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RIESGO
abrir ↗Exploit-DB
Grav CMS 2.0.7 - RCE
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RIESGO
abrir ↗GitHub PoC★ 1
Poc of CVE-2026-13753
Certain HP DeskJet All in One – Potential Information Disclosure
41RIESGO
abrir ↗GitHub PoC
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC★ 11
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir ↗GitHub PoC★ 2
Keycloak reset-credentials flow bypass
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir ↗GitHub PoC
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RIESGO
abrir ↗GitHub PoC★ 1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RIESGO
abrir ↗VulnCheck XDB
initial-access
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir ↗Exploit-DB
Wolf CMS 0.8.3.1 - RCE v
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RIESGO
abrir ↗GitHub PoC
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.