Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
initial-access
CVE-2023-3864614 jul 2026
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC15
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL14 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL14 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF)
CVE-2026-46457HIGH14 jul 2026
Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
41RIESGO
abrir
GitHub PoC
asoka666/Cve-2020-11023
CVE-2020-11023MEDIUMbajo ataque14 jul 2026
Potential XSS vulnerability in jQuery
85RIESGO
abrir
Metasploit600
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
CVE-2026-15409CRITICALbajo ataqueransomware14 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC
This contains the Dockerfile for building and reproduing shellshock
CVE-2014-7169CRITICALbajo ataque14 jul 2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
GitHub PoC8
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.
CVE-2026-23744CRITICAL14 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC1
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
CVE-2026-26718CRITICAL14 jul 2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att
48RIESGO
abrir
GitHub PoC3
CVE-2026-0740
CVE-2026-0740CRITICAL14 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
GitHub PoC
Defensive single-target self-check for Langflow CVE-2025-3248 exposure
CVE-2025-3248CRITICALbajo ataqueransomware14 jul 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-49049HIGH14 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RIESGO
abrir
GitHub PoC65
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
本次个人漏洞研究进展成果
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC8
Bartixxx32/CVE-2026-43499-OnePlus15
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46456 — Apache Camel camel-aws2-sqs inbound message-attribute header injection (Camel control-header injection via sqs:SendMessage → downstream producer steering / RCE)
CVE-2026-46456CRITICAL13 jul 2026
Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46455 — Apache Camel camel-keycloak missing TokenVerifier.IS_ACTIVE check (expired access tokens accepted)
CVE-2026-46455CRITICAL13 jul 2026
Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
48RIESGO
abrir
GitHub PoC1
Mendeteksi versi (passive detection) & Exploitation CVE POC
CVE-2026-56291CRITICALbajo ataque13 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RIESGO
abrir
GitHub PoC3
Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830
CVE-2026-57830HIGH13 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7
41RIESGO
abrir
GitHub PoC4
Unauthenticated Stored XSS in Joomla Helix Ultimate (JoomShaper) <= 2.2.6
CVE-2026-57829HIGH13 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
41RIESGO
abrir
GitHub PoC
CVE-2025-33073 Research writeup
CVE-2025-33073HIGHbajo ataque13 jul 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir
GitHub PoC
Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and execute commands on team servers.
CVE-2026-34048CRITICAL13 jul 2026
Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
48RIESGO
abrir
GitHub PoC1
CVE-2026-6307 - Google Chrome V8 Turbofan Type Confusion Sandbox Escape - PoC & Analysis | CVSS 8.8 HIGH | AMN SECURITY
CVE-2026-6307HIGH13 jul 2026
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)
CVE-2026-43867CRITICAL13 jul 2026
Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter
48RIESGO
abrir
GitHub PoC1
CVE-2026-40047 - Apache Camel Docling CLI Argument Injection - PoC & Analysis | CVSS 9.1 CRITICAL | AMN SECURITY
CVE-2026-40047CRITICAL13 jul 2026
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
48RIESGO
abrir
GitHub PoC
CVE-2026-49049 Helix3 (JoomShaper) Joomla Unauthenticated AJAX RCE Scanner
CVE-2026-49049HIGH13 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RIESGO
abrir
GitHub PoC6
Multi OS Support: Version for MacOS/Linux and Windows, Fully translated to English
CVE-2026-43499HIGH13 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
nuclei template for CVE-2026-56291
CVE-2026-56291CRITICALbajo ataque13 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RIESGO
abrir
GitHub PoC1
CVE-2026-48907 - Joomla JCE Editor Unauthenticated RCE - PoC & Analysis | CVSS 9.8 CRITICAL | AMN SECURITY
CVE-2026-48907CRITICALbajo ataque13 jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
anteriorpágina 65 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.