Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALbajo ataque08 jul 2026
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-56290CRITICAL08 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir
GitHub PoC
zero-trace7/CVE-2026-50229
CVE-2026-50229MEDIUM08 jul 2026
Apache Tomcat: XSS in number guess example
48RIESGO
abrir
GitHub PoC
eunho87/CVE-2021-42013
CVE-2021-42013CRITICALbajo ataqueransomware08 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
CVE-2026-40453CRITICAL08 jul 2026
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
48RIESGO
abrir
GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
CVE-2026-53359HIGH08 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC
CVE-2026-43499 - Draft
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC5
CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploader.
CVE-2026-56290CRITICAL08 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir
GitHub PoC3
CVE-2026-19874
CVE-2026-19874CRITICAL08 jul 2026
Konami's Metal Gear Online 3 contains a heap-based buffer overflow
48RIESGO
abrir
GitHub PoC12
Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.
CVE-2026-44825HIGH08 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RIESGO
abrir
GitHub PoC7
CVE-2026-43499
CVE-2026-43499HIGH08 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC2
Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal
CVE-2026-40047CRITICAL08 jul 2026
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware08 jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC1
Blocking the DirtyFrag Linux LPE chain (CVE-2026-43284 / CVE-2026-43500) at runtime with a Cilium Tetragon TracingPolicy
CVE-2026-43284HIGH08 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
Exploit-DB
Langflow 1.9.0 - RCE
CVE-2026-33017CRITICALbajo ataquewebappsmultiple08 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
aykhan32/CVE-2026-51788
CVE-2026-51788HIGH08 jul 2026
An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification
41RIESGO
abrir
GitHub PoC2
Verificador de Vulnerabilidad: Bad Epoll (CVE-2026-46242)
CVE-2026-46242HIGH08 jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RIESGO
abrir
GitHub PoC
CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC
CVE-2026-33017CRITICALbajo ataque08 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC16
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.
CVE-2026-57239HIGH08 jul 2026
Foxit PDF Editor/Reader Local Privilege Escalation
41RIESGO
abrir
Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
CVE-2026-56290CRITICALwebappsmultiple08 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir
Exploit-DB
Krayin CRM v2.2.x - Authenticated Remote Code Execution
CVE-2026-38526CRITICALwebappsmultiple08 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware08 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque08 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
Exploit-DB
Tenable Nessus 10.12.1 - SQL Injection
CVE-2026-57588LOWwebappsmultiple07 jul 2026
SQL Injection in Nessus via Malicious Scan Result File Import
28RIESGO
abrir
Exploit-DB
Flowise 3.1.3 - arbitrary code execution
CVE-2026-58057LOWwebappsmultiple07 jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RIESGO
abrir
GitHub PoC
CVE-2021-3156 (Baron Samedit) Report and Research
CVE-2021-3156HIGHbajo ataque07 jul 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque07 jul 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware07 jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE
CVE-2026-12277HIGH07 jul 2026
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal
41RIESGO
abrir
GitHub PoC1
A17-ba/CVE-2026-51119
CVE-2026-51119CRITICAL07 jul 2026
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co
48RIESGO
abrir
anteriorpágina 73 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.