Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC
Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape
CVE-2026-53362HIGHbajo ataque03 jul 2026
ipv6: account for fraggap on the paged allocation path
71RIESGO
abrir
GitHub PoC2
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter
CVE-2026-56290CRITICAL03 jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir
GitHub PoC
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore.
CVE-2026-53753CRITICAL03 jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RIESGO
abrir
GitHub PoC5
☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE
CVE-2026-44825HIGH03 jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-8451HIGH03 jul 2026
Insufficient input validation leading to memory overread
46RIESGO
abrir
GitHub PoC1
1beelze/CVE-2026-11387
CVE-2026-11387CRITICAL03 jul 2026
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware03 jul 2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC4
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
CVE-2026-28995HIGH03 jul 2026
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
41RIESGO
abrir
GitHub PoC
Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0
CVE-2026-36851HIGH03 jul 2026
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
41RIESGO
abrir
GitHub PoC1
FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168
CVE-2026-12166MEDIUM02 jul 2026
CVE-2026-12166
33RIESGO
abrir
GitHub PoC1
Proof of concept for CVE-2026-36027 and CVE-2026-36028
CVE-2026-36027MEDIUM02 jul 2026
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via
33RIESGO
abrir
GitHub PoC
Proof-of-concept exploit and lab environment for CVE-2026-25194
CVE-2026-25194LOW02 jul 2026
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve
8RIESGO
abrir
GitHub PoC3
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
CVE-2025-57819CRITICALbajo ataque02 jul 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC2
dinosn/CVE-2026-25243-debugfree
CVE-2026-25243HIGH02 jul 2026
redis-server RESTORE invalid memory access may allow remote code execution
41RIESGO
abrir
GitHub PoC
attarwahyup/Netscaler-CVE-2026-8451
CVE-2026-8451HIGH02 jul 2026
Insufficient input validation leading to memory overread
46RIESGO
abrir
GitHub PoC
CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)
CVE-2026-54477MEDIUM02 jul 2026
Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
33RIESGO
abrir
GitHub PoC
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
CVE-2026-13768CRITICAL02 jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RIESGO
abrir
GitHub PoC2
Python POC, Exploit for CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque02 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
GitHub PoC
Crawl4AI <= 0.8.6 pre-auth RCE via AST sandbox escape (gi_frame.f_back.f_builtins chain) — CVSS 10.0
CVE-2026-53753CRITICAL02 jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-27877HIGHbajo ataqueransomware02 jul 2026
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat
98RIESGO
abrir
GitHub PoC7
SimpleHelp OIDC Authentication Bypass PoC
CVE-2026-48558CRITICAL02 jul 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-52813CRITICAL02 jul 2026
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque02 jul 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC1
kaleth4/CVE-2026-20896
CVE-2026-20896CRITICAL02 jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RIESGO
abrir
GitHub PoC
BastianXploited/CVE-2026-0740-mass
CVE-2026-0740CRITICAL02 jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALbajo ataque02 jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48558CRITICAL02 jul 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
75RIESGO
abrir
GitHub PoC
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52813CRITICAL02 jul 2026
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RIESGO
abrir
GitHub PoC
kaleth4/CVE-2026-55200
CVE-2026-55200CRITICAL02 jul 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir
GitHub PoC
CVE-2025-5777 Research writeup
CVE-2025-5777CRITICALbajo ataqueransomware02 jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
anteriorpágina 78 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.