Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleicritical
IBM Data Risk Manager - Hardcoded Credentials
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RIESGO
abrir
Nucleicritical
OpenSMTPD 6.4.0-6.6.1 - Remote Code Execution
CVE-2020-7247CRITICALbajo ataque
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Nucleicritical
SolarWinds Serv-U FTP - Remote Code Execution
CVE-2021-35211CRITICALbajo ataqueransomware
Serv-U Remote Memory Escape Vulnerability
100RIESGO
abrir
Nucleicritical
RealTek AP Router SDK - Arbitrary Command Injection
CVE-2021-35394CRITICALbajo ataque
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as
95RIESGO
abrir
Nucleihigh
PowerDNS Authoritative Server - Denial of Service
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE
30RIESGO
abrir
Nucleihigh
Oracle WebLogic Server - Unauthorized Access
CVE-2023-21839HIGHbajo ataque
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
Nucleicritical
VMWare Aria Operations - Remote Code Execution
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RIESGO
abrir
Nucleicritical
Acronis Cyber Infrastructure - Default Password
CVE-2023-45249CRITICALbajo ataque
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastruct
85RIESGO
abrir
Nucleicritical
Apache ActiveMQ - Remote Code Execution
CVE-2023-46604CRITICALbajo ataqueransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RIESGO
abrir
Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
CVE-2024-23897CRITICALbajo ataqueransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
CVE-2024-45519CRITICALbajo ataque
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RIESGO
abrir
Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
CVE-2025-14847HIGHbajo ataque
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RIESGO
abrir
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RIESGO
abrir
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RIESGO
abrir
Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
CVE-2026-0257HIGHbajo ataqueransomware
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
Nucleicritical
SonicWall SMA1000 - Server-Side Request Forgery
CVE-2026-15409CRITICALbajo ataque
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
98RIESGO
abrir
Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CVE-2026-1731CRITICALbajo ataqueransomware
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RIESGO
abrir
Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RIESGO
abrir
Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
CVE-2026-39987CRITICALbajo ataque
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RIESGO
abrir
Nucleicritical
Samba Printing Subsystem - Remote Code Execution
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
Nucleicritical
Joomla! Component PrayerCenter 3.0.2 - SQL Injection
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil
50RIESGO
abrir
Nucleihigh
WordPress Site Editor <=1.1.1 - Local File Inclusion
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
Nucleihigh
AxxonSoft Axxon Next - Local File Inclusion
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
23RIESGO
abrir
anteriorpágina 117 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.