Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.703 exploits
Exploit-DB
Grav CMS 2.0.7 - RCE
CVE-2026-65008CRITICALwebappsmultiple01 sep 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RIESGO
abrir
GitHub PoC
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
CVE-2021-44228CRITICALbajo ataqueransomware01 sep 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
CVE-2025-50455CRITICALwebappsmultiple01 sep 2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RIESGO
abrir
GitHub PoC
CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass
CVE-2026-24061CRITICALbajo ataque01 sep 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC2
Keycloak reset-credentials flow bypass
CVE-2026-18963CRITICAL01 sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
CVE-2026-33017CRITICALbajo ataque01 sep 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
Exploit-DB
Langflow 1.8.4 - Path Traversal to Remote Code Execution
CVE-2026-5027HIGHwebappsmultiple31 ago 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 ago 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 ago 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALbajo ataque31 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALbajo ataque31 ago 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RIESGO
abrir
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 ago 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RIESGO
abrir
Exploit-DB
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
CVE-2025-60689MEDIUMwebappshardware31 ago 2026
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200
38RIESGO
abrir
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
Shellshock CVE-2014-6271 vulnerable CGI lab
CVE-2014-6271CRITICALbajo ataque30 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2025-5777CRITICALbajo ataqueransomware30 ago 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL30 ago 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC16
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICALbajo ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque30 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 ago 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RIESGO
abrir
GitHub PoC
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
GitHub PoC2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RIESGO
abrir
GitHub PoC
Log4Shell CVE-2021-44228 vulnerable lab
CVE-2021-44228CRITICALbajo ataqueransomware30 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
CVE-2018-7600CRITICALbajo ataqueransomware30 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALbajo ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.