Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.846exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
GitHub PoC72
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343HIGH02 sep 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RIESGO
abrir
GitHub PoC2
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
CVE-2026-65349MEDIUM02 sep 2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RIESGO
abrir
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHbajo ataque02 sep 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RIESGO
abrir
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 sep 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RIESGO
abrir
Exploit-DB
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
CVE-2026-41456MEDIUMwebappsmultiple02 sep 2026
Bludit CMS Reflected XSS via Search Plugin
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALbajo ataque02 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC
Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)
CVE-2011-252302 sep 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC1
Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).
CVE-2011-252302 sep 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Exploit-DB
Marimo 0.20.4 - RCE
CVE-2026-39987CRITICALbajo ataquewebappsmultiple02 sep 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC5
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 sep 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RIESGO
abrir
GitHub PoC10
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 sep 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RIESGO
abrir
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 sep 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RIESGO
abrir
Exploit-DB
miniOrange 5.4.3 - Unauthenticated Auth Bypass
CVE-2026-15013CRITICALwebappsmultiple01 sep 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RIESGO
abrir
GitHub PoC1
Ghxstsec/CVE-2026-39987
CVE-2026-39987CRITICALbajo ataque01 sep 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
GitHub PoC
pervinzahidli/CVE-2026-75855
CVE-2026-75855HIGH01 sep 2026
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RIESGO
abrir
Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
CVE-2025-50455CRITICALwebappsmultiple01 sep 2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RIESGO
abrir
Exploit-DB
Grav CMS 2.0.7 - RCE
CVE-2026-65008CRITICALwebappsmultiple01 sep 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RIESGO
abrir
GitHub PoC1
Poc of CVE-2026-13753
CVE-2026-13753HIGH01 sep 2026
Certain HP DeskJet All in One – Potential Information Disclosure
41RIESGO
abrir
GitHub PoC
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
CVE-2026-33017CRITICALbajo ataque01 sep 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC11
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
CVE-2026-82329CRITICALbajo ataque01 sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RIESGO
abrir
GitHub PoC2
Keycloak reset-credentials flow bypass
CVE-2026-18963CRITICAL01 sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
CVE-2021-44228CRITICALbajo ataqueransomware01 sep 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
CVE-2026-82221HIGH01 sep 2026
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RIESGO
abrir
GitHub PoC1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
CVE-2026-82592CRITICAL01 sep 2026
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware01 sep 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware01 sep 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3493HIGHbajo ataque01 sep 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Exploit-DB
Wolf CMS 0.8.3.1 - RCE v
CVE-2026-67206HIGHwebappsmultiple01 sep 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RIESGO
abrir
GitHub PoC
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
CVE-2026-14662HIGH01 sep 2026
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.