Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.043exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.260VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir ↗GitHub PoC★ 1
bekwiner/cve-2026-47777
Mastodon has a consent-check bypass in its remote Collections
41RIESGO
abrir ↗GitHub PoC
jaf0rk/CVE-2026-14431
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
41RIESGO
abrir ↗GitHub PoC★ 1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RIESGO
abrir ↗GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RIESGO
abrir ↗GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RIESGO
abrir ↗GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research.
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
75RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 46
CVE-2026-50416: Windows 11 KASLR bypass
Win32k Information Disclosure Vulnerability
28RIESGO
abrir ↗GitHub PoC★ 7
CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗GitHub PoC★ 1
MiaPatsune/cve-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RIESGO
abrir ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RIESGO
abrir ↗VulnCheck XDB
info-leak
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗GitHub PoC★ 775
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir ↗GitHub PoC
bibotai/secveri-cve-2026-50011-positive
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RIESGO
abrir ↗GitHub PoC★ 1
CVE-2026-33017 Exploit | by infrar3d
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RIESGO
abrir ↗GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗GitHub PoC★ 2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RIESGO
abrir ↗GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RIESGO
abrir ↗GitHub PoC★ 40
Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Sana-404/CVE-2026-8838-Mitigation-and-Detection
Remote Code Execution via eval() Injection in amazon-redshift-python-driver
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.