Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque10 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque10 jul 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
unpredictable21/halo-2.25.4-backup-write-CVE-2026-67920
CVE-2026-67920HIGH10 jul 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.Migration
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-49049HIGH10 jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RIESGO
abrir
GitHub PoC
caspy123/CVE-2026-43499
CVE-2026-43499HIGH10 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM10 jul 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
GitHub PoC1
inforcqb/CVE-2026-43499-pja110
CVE-2026-43499HIGH10 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
CVE-2026-28992 IOHIDFamily FastPathUserClient race condition PoC — security research
CVE-2026-28992MEDIUM10 jul 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RIESGO
abrir
GitHub PoC1
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)
CVE-2026-40858HIGH10 jul 2026
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
41RIESGO
abrir
GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
CVE-2025-60787HIGH10 jul 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RIESGO
abrir
GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
CVE-2026-50979HIGH10 jul 2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RIESGO
abrir
GitHub PoC
sudoand3rs0n/CVE-2025-5548
CVE-2025-5548MEDIUM10 jul 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir
Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
CVE-2026-3576HIGH10 jul 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RIESGO
abrir
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware10 jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC1
lieehrdiansyah12/CVE-2026-43503
CVE-2026-43503HIGH09 jul 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC
endusdksla/xwiki-cve-2025-24893
CVE-2025-24893CRITICALbajo ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
cazzysoci/cve-2026-48908
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir
GitHub PoC
Laboratory validation of CVE-2026-48908 in Joomla SP Page Builder, covering unauthorized icon upload, PHP file write, code execution as www-data, auditd and PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes Polish and English reports.
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir
GitHub PoC1
0x00phantom-hat/CVE-2026-12400-Exploit
CVE-2026-12400MEDIUM09 jul 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
33RIESGO
abrir
GitHub PoC
PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)
CVE-2026-49230MEDIUM09 jul 2026
Apache APISIX: Authentication bypass in jwe-decrypt
33RIESGO
abrir
GitHub PoC61
OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation
CVE-2026-43499HIGH09 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
Public disclosure for CVE-2026-52100 (CSRF) & CVE-2026-52101 (SSRF) in linx-server. MITRE assigned the CVEs; this repo provides a public reference and helps affected users understand the risk.
CVE-2026-52100HIGH09 jul 2026
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware09 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL09 jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir
GitHub PoC
CVE-2026-50746... - Draft
CVE-2026-50746CRITICAL09 jul 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-8037CRITICALbajo ataque09 jul 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware09 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque09 jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
anteriorpágina 71 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.