Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
GitHub PoC
ctnBobong32/CVE-2026-43499-so-build
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 47
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC★ 1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
NeseOS-Corp/CVE-2026-50657
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RIESGO
abrir ↗GitHub PoC★ 1
Remote Code Execution (RCE) in Yamcs Mission Control System via Java Statement Injection in Yarch SQL Double-Quoted IdentifiersRemote Code Execution (RCE) in Yamcs Mission Control System via Java Statement Injection in Yarch SQL Double-Quoted Identifiers
Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
48RIESGO
abrir ↗GitHub PoC★ 4
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗GitHub PoC
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗GitHub PoC
exploit for CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗GitHub PoC
CVE-2025-60357- NoSQL(MongoDB) Injection POC
AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv
41RIESGO
abrir ↗GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RIESGO
abrir ↗VulnCheck XDB
initial-access
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir ↗GitHub PoC★ 21
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗GitHub PoC★ 2
Raimu0x19/CVE-2026-13001
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RIESGO
abrir ↗GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-15409
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir ↗GitHub PoC★ 1
Samsung libimagecodec.quram.so OOB Write PoC
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RIESGO
abrir ↗GitHub PoC
firstlax6t/CVE-2026-36669-FengOffice
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote
48RIESGO
abrir ↗GitHub PoC
lamaper/CVE-2026-52199
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/
48RIESGO
abrir ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RIESGO
abrir ↗GitHub PoC★ 15
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir ↗GitHub PoC
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF)
Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
41RIESGO
abrir ↗GitHub PoC
Defensive single-target self-check for Langflow CVE-2025-3248 exposure
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗GitHub PoC★ 8
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗GitHub PoC★ 3
CVE-2026-0740
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.