Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.183exploits catalogados
37.028CVEs con explotación pública
24.695probados en laboratorio
80.183 exploits
GitHub PoC1
SCAN END POC THE CVE-2024-4367
CVE-2024-4367MEDIUM25 jun 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RIESGO
abrir
GitHub PoC34
CVE-2026-43503
CVE-2026-43503HIGH25 jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RIESGO
abrir
GitHub PoC
Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.
CVE-2019-905325 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-20230HIGH25 jun 2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
63RIESGO
abrir
GitHub PoC1
CVE-2026-7574
CVE-2026-7574HIGH25 jun 2026
Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
41RIESGO
abrir
GitHub PoC
CVE-2026-55584 — phpSysInfo IP Allowlist Bypass
CVE-2026-55584HIGH25 jun 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-61155MEDIUM25 jun 2026
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in
33RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque25 jun 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL25 jun 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC
7whyex/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALbajo ataqueransomware25 jun 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque25 jun 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
GitHub PoC
Squamity/CVE-2026-8181-PoC
CVE-2026-8181CRITICAL25 jun 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC1
W5M1n9/Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230
CVE-2026-20230HIGH25 jun 2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
63RIESGO
abrir
GitHub PoC
Lab — Privilege Escalation via Dirty Cow CVE-2016-5195 | 4Geeks Academy
CVE-2016-5195HIGHbajo ataque25 jun 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-58034MEDIUMbajo ataque24 jun 2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RIESGO
abrir
GitHub PoC1
CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS
CVE-2026-39275MEDIUM24 jun 2026
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
33RIESGO
abrir
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALbajo ataqueransomware24 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
CraftCMS CVE-2025-32432 - Clean PoC
CVE-2025-32432CRITICALbajo ataque24 jun 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-8461 - Draft
CVE-2026-8461HIGH24 jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RIESGO
abrir
GitHub PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALbajo ataque24 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC3
Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover
CVE-2026-12416CRITICAL24 jun 2026
Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
48RIESGO
abrir
GitHub PoC1
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution
CVE-2026-38526CRITICAL24 jun 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir
GitHub PoC1
Proof of concept for CVE-2026-56111, an out-of-bounds write in the M421 G-code handler of Marlin Firmware
CVE-2026-56111HIGH24 jun 2026
Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
41RIESGO
abrir
GitHub PoC
ROOT TOOL
CVE-2022-37706HIGH24 jun 2026
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALbajo ataque24 jun 2026
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
GitHub PoC
CVE-2026-31431 getroot from a Turkish Cryptominer
CVE-2026-31431HIGHbajo ataque24 jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware24 jun 2026
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
GitHub PoC2
CVE-2026-48908
CVE-2026-48908CRITICAL24 jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RIESGO
abrir
GitHub PoC63
CVE-2026-45504 Microsoft Exchange File Read
CVE-2026-45504HIGH24 jun 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RIESGO
abrir
anteriorpágina 85 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.