Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Metasploit600
SimpleHelp OIDC Authentication Bypass Remote Code Execution
CVE-2026-48558CRITICAL12 jun 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
75RIESGO
abrir
GitHub PoC2
CVE-2026-35273
CVE-2026-35273CRITICALbajo ataqueransomware12 jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RIESGO
abrir
GitHub PoC4
CVE-2026-35273
CVE-2026-35273CRITICALbajo ataqueransomware12 jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RIESGO
abrir
GitHub PoC1
CVE-2026-50751 — Check Point IKEv1 Authentication Bypass
CVE-2026-50751CRITICALbajo ataqueransomware12 jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RIESGO
abrir
GitHub PoC1
Safely detect whether a SolarWinds Serv-U host is vulnerable to CVE-2026-28318
CVE-2026-28318HIGHbajo ataque12 jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RIESGO
abrir
GitHub PoC
rootdirective-sec/CVE-2026-46645-Analysis-Lab
CVE-2026-46645MEDIUM12 jun 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
33RIESGO
abrir
GitHub PoC
Cisco Unified Communications Manager (Unified CM) deployments affected by CVE-2026-20230.
CVE-2026-20230HIGH12 jun 2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
63RIESGO
abrir
GitHub PoC13
watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253
CVE-2026-20253CRITICALbajo ataque12 jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RIESGO
abrir
GitHub PoC3
CVE-2026-48907
CVE-2026-48907CRITICALbajo ataque12 jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware12 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC
Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Manager) to achieve Remote Code Execution (RCE). For educational use only.
CVE-2025-57819CRITICALbajo ataque12 jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
GitHub PoC4
Toolkit for CVE-2025-55182, also known as React2Shell.
CVE-2025-55182CRITICALbajo ataqueransomware12 jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC3
CVE-2026-25089
CVE-2026-25089CRITICALbajo ataque12 jun 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RIESGO
abrir
GitHub PoC
anirudhmakkar/cve-2026-7665
CVE-2026-7665MEDIUM11 jun 2026
Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
33RIESGO
abrir
GitHub PoC
byte16384/CVE-2026-49492-PoC
CVE-2026-49492HIGH11 jun 2026
Markdown Preview Enhanced OS Command Injection in External File and Link Opening
41RIESGO
abrir
GitHub PoC
kaleth4/CVE-2021-4045
CVE-2021-4045CRITICAL11 jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL11 jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10795HIGH11 jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RIESGO
abrir
GitHub PoC2
CVE-2026-10795 – UpdraftPlus Authentication Bypass
CVE-2026-10795HIGH11 jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL11 jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46
CVE-2026-40791HIGH11 jun 2026
WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-23479 Redis Use-After-Free vulnerability detection tool
CVE-2026-23479HIGH11 jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RIESGO
abrir
GitHub PoC
Cyber-DarkNay/CVE-2026-45034
CVE-2026-45034CRITICAL11 jun 2026
PhpSpreadsheet: File::prohibitWrappers bypass
48RIESGO
abrir
GitHub PoC1
PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em CTF/laboratório, com prefixos pré-configurados para reduzir o tempo de extração e mensagens explicativas em português.
CVE-2019-905311 jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC4
CVE-2026-10520
CVE-2026-10520CRITICAL11 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC1
Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth
CVE-2026-28699HIGH11 jun 2026
Gitea Basic Auth bypasses OAuth2 access token scopes
41RIESGO
abrir
GitHub PoC
CVE-2026-10520 and CVE-2026-10523
CVE-2026-10520CRITICAL11 jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RIESGO
abrir
GitHub PoC
Cyber-DarkNay/CVE-2026-23550
CVE-2026-23550CRITICAL11 jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RIESGO
abrir
anteriorpágina 97 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.