Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC2
Linux 内核升级指南 - 修复 CVE-2026-53359
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC6
Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — covers every operational scenario. / KVM/x86 shadow MMU 虚拟机逃逸漏洞(CVE-2026-53359)的完整修复方案集合。 从零停机热修复到内核升级,覆盖所有运维场景。
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC2
IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE (CVE-2026-43284/43500). CC0.
CVE-2026-43284HIGH07 jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RIESGO
abrir
GitHub PoC
CVE-2026-53359 - Draft
CVE-2026-53359HIGH07 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
Exploit-DB
Hydra - Stack Buffer Overflow
CVE-2026-56766HIGHremotelinux07 jul 2026
Hydra - Stack Buffer Overflow in NTLM Authentication Handler
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.
CVE-2026-54350CRITICAL07 jul 2026
Budibase: Anonymous NoSQL operator injection via published-app query templates
48RIESGO
abrir
Exploit-DB
Tenable Nessus 10.12.1 - SQL Injection
CVE-2026-57588LOWwebappsmultiple07 jul 2026
SQL Injection in Nessus via Malicious Scan Result File Import
28RIESGO
abrir
GitHub PoC
Vtiger CRM 8.3.0, 8.4.0 Module Import Authenticated RCE PoC
CVE-2026-23698HIGH07 jul 2026
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
41RIESGO
abrir
Exploit-DB
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
CVE-2026-44225CRITICALwebappsmultiple06 jul 2026
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
48RIESGO
abrir
GitHub PoC
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
Exploit-DB
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
CVE-2026-49069HIGHwebappsmultiple06 jul 2026
WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability
56RIESGO
abrir
Exploit-DB
Joomla Extension 4.1.4 - PHP Object injection
CVE-2026-48909CRITICALwebappsphp06 jul 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RIESGO
abrir
Exploit-DB
KeepInMind 0.8.4.2 - Stored XSS
CVE-2026-9271MEDIUMwebappsmultiple06 jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RIESGO
abrir
Exploit-DB
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
CVE-2026-36213HIGHlocalwindows06 jul 2026
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e
41RIESGO
abrir
GitHub PoC1
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution
CVE-2024-39024HIGH06 jul 2026
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
41RIESGO
abrir
GitHub PoC1
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
CVE-2026-49352CRITICAL06 jul 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
48RIESGO
abrir
GitHub PoC7
jaf0rk/CVE-2026-14382
CVE-2026-14382CRITICAL06 jul 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL06 jul 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RIESGO
abrir
GitHub PoC
CVE-2012-2122 - MySQL Authentication Bypass
CVE-2012-212206 jul 2026
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-40022: Apache Camel camel-platform-http-main authentication bypass on non-root context paths
CVE-2026-40022HIGH06 jul 2026
Apache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
41RIESGO
abrir
GitHub PoC
HTB "Abducted" write-up. Exploit CVE-2026-4480 (Samba RCE) → SMB wide links → systemd → root. Full methodology and flags.
CVE-2026-4480CRITICAL06 jul 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
GitHub PoC
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value.
CVE-2026-25555CRITICAL06 jul 2026
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
63RIESGO
abrir
GitHub PoC24
imbas007/CVE-2026-48282
CVE-2026-48282CRITICAL06 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RIESGO
abrir
GitHub PoC
CVE-2026-24061-PoC
CVE-2026-24061CRITICALbajo ataque06 jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.
CVE-2026-38526CRITICAL06 jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC
AF_ALG/splice 기반 Linux Page Cache 변조 취약점 분석 및 대응 실습
CVE-2026-31431HIGHbajo ataque06 jul 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC1
Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec
CVE-2026-33454CRITICAL06 jul 2026
Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)
48RIESGO
abrir
GitHub PoC
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
CVE-2025-55182CRITICALbajo ataqueransomware06 jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-33453: Apache Camel camel-coap header injection to RCE via camel-exec
CVE-2026-33453CRITICAL06 jul 2026
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-27172: Apache Camel camel-consul ConsulRegistry Java deserialization (RCE)
CVE-2026-27172HIGH06 jul 2026
Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
41RIESGO
abrir
anteriorpágina 75 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.