Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC
ubaydev/CVE-2026-11551-PoC
CVE-2026-11551CRITICAL21 jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RIESGO
abrir
GitHub PoC
Public disclosure for CVE-2026-43655 AppleM2ScalerCSCDriver use-after-free
CVE-2026-43655HIGH21 jun 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macO
41RIESGO
abrir
GitHub PoC
Luisbuilds-data/cve-2024-1086-writeup
CVE-2024-1086HIGHbajo ataqueransomware21 jun 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RIESGO
abrir
GitHub PoC
adriannurrr/CVE-2026-45321-Tanstack
CVE-2026-45321CRITICALbajo ataqueransomware21 jun 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RIESGO
abrir
GitHub PoC
JFrog AppTrust lifecycle policy enforcement demo — shows release gate blocking CVE-2022-22965 (Spring4Shell) with waiver request flow
CVE-2022-22965CRITICALbajo ataque21 jun 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque21 jun 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC
POC for CVE-2025-24893
CVE-2025-24893CRITICALbajo ataque21 jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
GitHub PoC
1fox23/CVE-2026-32202
CVE-2026-32202MEDIUMbajo ataque21 jun 2026
Windows Shell Spoofing Vulnerability
75RIESGO
abrir
GitHub PoC
POC for CVE-2025-32463
CVE-2025-32463CRITICALbajo ataque21 jun 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
GitHub PoC23
CVE-2026-48909 PoC
CVE-2026-48909CRITICAL21 jun 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RIESGO
abrir
GitHub PoC
alexlanum/CVE-2026-32202
CVE-2026-32202MEDIUMbajo ataque21 jun 2026
Windows Shell Spoofing Vulnerability
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL21 jun 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
GitHub PoC
aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation
CVE-2023-46604CRITICALbajo ataqueransomware20 jun 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL20 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
GitHub PoC2
CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0.
CVE-2026-37149HIGH20 jun 2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil
41RIESGO
abrir
GitHub PoC
ClearLotus-git/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL20 jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
GitHub PoC2
Missing Authorization to Unauthenticated File Modification
CVE-2026-11912HIGH20 jun 2026
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
41RIESGO
abrir
GitHub PoC3
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via Cloud Files API + NTFS junction trickery. Forces Defender to write malicious payloads to System32 with SYSTEM rights. ⚠️ Actively exploited in wild. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. 🛡️ Educational PoC only.
CVE-2026-41091HIGHbajo ataque20 jun 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC
Technical analysis of Apache Tomcat CVE-2024-50379, covering root cause, exploitation conditions, detection strategies, and mitigation techniques.
CVE-2024-50379CRITICAL20 jun 2026
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RIESGO
abrir
GitHub PoC1
GadaLuBau1337/CVE-2026-44578
CVE-2026-44578HIGH20 jun 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RIESGO
abrir
GitHub PoC
Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053
CVE-2019-905320 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
CVE-2026-49975HIGH20 jun 2026
Apache HTTP Server: mod_http2 denial of service
53RIESGO
abrir
GitHub PoC
xxconi/CVE-2026-4782
CVE-2026-4782MEDIUM19 jun 2026
Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
33RIESGO
abrir
GitHub PoC1
Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RIESGO
abrir
GitHub PoC
AlexMihailEngineer/CVE-2026-11784-Optimole-CSRF
CVE-2026-11784MEDIUM19 jun 2026
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action
33RIESGO
abrir
GitHub PoC
Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).
CVE-2026-43515CRITICAL19 jun 2026
Apache Tomcat: Security constraints not correctly applied
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL19 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RIESGO
abrir
GitHub PoC2
POC for CVE-2026-25212
CVE-2026-25212CRITICAL19 jun 2026
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileg
48RIESGO
abrir
GitHub PoC
CVE-2026-48611- authentication bypass in phpBB
CVE-2026-48611CRITICAL19 jun 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
anteriorpágina 89 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.