Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.043exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-60137MEDIUMbajo ataque17 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
CVE-2026-60137MEDIUMbajo ataque17 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RIESGO
abrir
GitHub PoC
jaf0rk/CVE-2026-14431
CVE-2026-14431HIGH17 jul 2026
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
41RIESGO
abrir
GitHub PoC1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48205CRITICAL17 jul 2026
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RIESGO
abrir
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
CVE-2026-15583HIGH17 jul 2026
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
CVE-2026-47323CRITICAL17 jul 2026
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RIESGO
abrir
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research.
CVE-2026-46442CRITICAL17 jul 2026
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC46
CVE-2026-50416: Windows 11 KASLR bypass
CVE-2026-50416LOW17 jul 2026
Win32k Information Disclosure Vulnerability
28RIESGO
abrir
GitHub PoC7
CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALbajo ataque17 jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMbajo ataque17 jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque17 jul 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC775
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALbajo ataque17 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
bibotai/secveri-cve-2026-50011-positive
CVE-2026-50011HIGH16 jul 2026
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RIESGO
abrir
GitHub PoC1
CVE-2026-33017 Exploit | by infrar3d
CVE-2026-33017CRITICALbajo ataque16 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
CVE-2026-8388MEDIUM16 jul 2026
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RIESGO
abrir
GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque16 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
CVE-2026-58457CRITICAL16 jul 2026
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46726HIGH16 jul 2026
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RIESGO
abrir
GitHub PoC40
Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Sana-404/CVE-2026-8838-Mitigation-and-Detection
CVE-2026-8838CRITICAL16 jul 2026
Remote Code Execution via eval() Injection in amazon-redshift-python-driver
48RIESGO
abrir
anteriorpágina 61 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.