Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC1
CVE-2025-24813 - Apache Tomcat RCE via Session Deserialization - PoC Exploit
CVE-2025-24813CRITICALbajo ataque12 jul 2026
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78
CVE-2026-4631CRITICAL12 jul 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RIESGO
abrir
GitHub PoC
cve-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware12 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
CVE research-to-detection-signature engineering project: fingerprinting the vsftpd 2.3.4 backdoor (CVE-2011-2523) externally, at scale, with validated false-positive/negative handling - built in Python
CVE-2011-252312 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab
CVE-2023-4911HIGHbajo ataque12 jul 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
GitHub PoC
OS Command Injection in Health Check → Remote Code Execution
CVE-2026-59734HIGH11 jul 2026
Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
41RIESGO
abrir
GitHub PoC
WHS 4기 이희수. kr-vulhub 과제 제출물
CVE-2021-41773HIGHbajo ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.
CVE-2011-252311 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
PoC for jenkins 2.63 CVE-2019-1003030
CVE-2019-1003030CRITICALbajo ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHbajo ataque11 jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.
CVE-2012-1823CRITICALbajo ataque11 jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC
jini135wii/CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware11 jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware11 jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC1
CVE-2026-46242
CVE-2026-46242HIGH11 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RIESGO
abrir
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 jul 2026
@vendure/core has a SQL Injection vulnerability
43RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
41RIESGO
abrir
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALbajo ataque11 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RIESGO
abrir
GitHub PoC6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
CVE-2026-43501CRITICAL11 jul 2026
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29114
CVE-2026-29114LOW11 jul 2026
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
28RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
33RIESGO
abrir
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
41RIESGO
abrir
GitHub PoC1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
CVE-2026-57850HIGH11 jul 2026
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RIESGO
abrir
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RIESGO
abrir
GitHub PoC
1beelze/CVE-2026-14894
CVE-2026-14894CRITICAL11 jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RIESGO
abrir
GitHub PoC1
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
CVE-2026-13768CRITICAL11 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALbajo ataque11 jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware11 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-43798HIGHbajo ataque11 jul 2026
Grafana path traversal
100RIESGO
abrir
anteriorpágina 69 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.