Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.096exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.096 exploits
GitHub PoC
patched ffmpeg-tools for jellyfin to patch CVE-2026-8461 aka PixelSmash
CVE-2026-8461HIGH27 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RIESGO
abrir
GitHub PoC
Hunt-Benito/traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization
CVE-2026-48020HIGH27 jun 2026
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
41RIESGO
abrir
GitHub PoC
PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.
CVE-2026-5366CRITICAL27 jun 2026
Git Argument Injection in prefecthq/prefect
48RIESGO
abrir
GitHub PoC
CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness chain — missing auth, no extension validation, and an unsafe upload flag — that lets attackers pop a shell in 3 HTTP requests.
CVE-2026-48907CRITICALbajo ataque27 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque27 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALbajo ataque27 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC3
CVE-2026-0073-Android-ADBD-bypass-POC汉化版
CVE-2026-0073HIGH27 jun 2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RIESGO
abrir
GitHub PoC
kyukazamiqq/CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque27 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
GitHub PoC
Defensive analysis and non-weaponized validation of CVE-2016-5195 (Dirty COW), including root-cause research, patch analysis, and reproducible evidence.
CVE-2016-5195HIGHbajo ataque27 jun 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2026-24061CRITICALbajo ataque27 jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque27 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALbajo ataque27 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
GitHub PoC8
OpenSTAManager-RCE-Exploit-CVE-2026-38751
CVE-2026-38751HIGH27 jun 2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RIESGO
abrir
GitHub PoC1
WP Full Stripe Free <= 8.4.3 - Missing Authorization
CVE-2026-12432MEDIUM27 jun 2026
Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
33RIESGO
abrir
GitHub PoC
SugiB3o/CVE-2026-31431
CVE-2026-31431HIGHbajo ataque27 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
local
CVE-2026-31431HIGHbajo ataque27 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
GitHub PoC4
SQL Injection at Cacti
CVE-2026-40083HIGH27 jun 2026
Cacti: SQL Injection in managers.php
41RIESGO
abrir
GitHub PoC
Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061
CVE-2025-32432CRITICALbajo ataque27 jun 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC148
CVE-2026-43499 PoC
CVE-2026-43499HIGH27 jun 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
CVE-2026-33146MEDIUM26 jun 2026
Docmost's Public Share Search Exposes Metadata of Restricted Children
33RIESGO
abrir
GitHub PoC1
CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.
CVE-2026-24207CRITICAL26 jun 2026
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
63RIESGO
abrir
GitHub PoC4
aexdyhaxor/CVE-2026-43503-DirtyClone
CVE-2026-43503HIGH26 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
CVE-2026-34212MEDIUM26 jun 2026
Docmost page content has stored XSS via unsanitized attachment URLs
33RIESGO
abrir
GitHub PoC3
CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research
CVE-2026-20251HIGH26 jun 2026
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-26980CRITICAL26 jun 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
GitHub PoC
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
CVE-2026-34213MEDIUM26 jun 2026
Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
33RIESGO
abrir
GitHub PoC
Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration, and credential cracking prep.
CVE-2007-244726 jun 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-8088HIGHbajo ataqueransomware26 jun 2026
Path traversal vulnerability in WinRAR
93RIESGO
abrir
GitHub PoC
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
CVE-2026-34207HIGH26 jun 2026
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
41RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2026-26980CRITICAL26 jun 2026
Ghost has a SQL Injection in its Content API
85RIESGO
abrir
anteriorpágina 83 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.