Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.047exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
GitHub PoC40
Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
uname1able/CVE-2025-21333
CVE-2025-21333HIGHbajo ataque16 jul 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
CVE-2026-8388MEDIUM16 jul 2026
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RIESGO
abrir
GitHub PoC
Sana-404/CVE-2026-8838-Mitigation-and-Detection
CVE-2026-8838CRITICAL16 jul 2026
Remote Code Execution via eval() Injection in amazon-redshift-python-driver
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-34197HIGHbajo ataque16 jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL16 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a read to a destructive one (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46592HIGH16 jul 2026
Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware16 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC5
Next.js RSC RCE Exploit Tool (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware16 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
sadb98523-eng/CVE-2026-13001
CVE-2026-13001CRITICAL16 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RIESGO
abrir
GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.
CVE-2026-15409CRITICALbajo ataqueransomware16 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware16 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
KVM KernelCare + Januscape (CVE-2026-53359) verification & mitigation scripts
CVE-2026-53359HIGH16 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC
bibotai/secveri-cve-2026-50011-negative
CVE-2026-50011HIGH16 jul 2026
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RIESGO
abrir
GitHub PoC6
CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite
CVE-2026-43499HIGH16 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46726HIGH16 jul 2026
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RIESGO
abrir
GitHub PoC
bibotai/secveri-cve-2026-50011-positive
CVE-2026-50011HIGH16 jul 2026
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RIESGO
abrir
GitHub PoC2
syxlox/CVE-2026-50369
CVE-2026-50369HIGH16 jul 2026
Windows Remote Desktop Services Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC6
this is a modified POC of rz1027 for CVE-2026-20896
CVE-2026-20896CRITICAL16 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RIESGO
abrir
GitHub PoC1
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
CVE-2026-14894CRITICAL16 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
GitHub PoC2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
CVE-2026-58457CRITICAL16 jul 2026
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RIESGO
abrir
GitHub PoC3
🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no extraction) and exploit.py (deep analysis). Supports 11 DB types. Perfect for understanding SQL injection vulnerabilities. Only legal tests ⚠️ for educational & research purposes only.
CVE-2026-57821HIGH16 jul 2026
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
41RIESGO
abrir
GitHub PoC6
Proof of concept for CVE-2026-54992, an MSMQ remote-read integer overflow
CVE-2026-54992HIGH16 jul 2026
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
41RIESGO
abrir
GitHub PoC1
Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and reporting for penetration testing and security research.
CVE-2026-3180HIGH16 jul 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RIESGO
abrir
GitHub PoC4
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
CVE-2026-3891CRITICAL15 jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir
GitHub PoC3
A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).
CVE-2024-6387HIGH15 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
anteriorpágina 62 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.