Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.459 exploits
Exploit-DB
Feng Office 3.11.1.2 - SQL Injection
CVE-2024-6039MEDIUMwebappsphp10 abr 2025
Feng Office Workspaces sql injection
33RIESGO
abrir
Exploit-DB
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
CVE-2024-36424MEDIUMremotemultiple10 abr 2025
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RIESGO
abrir
Exploit-DB
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CVE-2024-7815MEDIUMwebappsphp10 abr 2025
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RIESGO
abrir
Exploit-DB
Cosy+ firmware 21.2s7 - Command Injection
CVE-2024-33896HIGHhardwaremultiple10 abr 2025
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due
41RIESGO
abrir
Exploit-DB
Typecho 1.3.0 - Race Condition
CVE-2024-35539MEDIUMwebappsphp10 abr 2025
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil
33RIESGO
abrir
Exploit-DB
PandoraFMS 7.0NG.772 - SQL Injection
CVE-2023-44088MEDIUMwebappsphp10 abr 2025
SQL Injection in Visual Console
33RIESGO
abrir
Exploit-DB
Centron 19.04 - Remote Code Execution (RCE)
CVE-2019-13024webappsphp10 abr 2025
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
28RIESGO
abrir
Exploit-DB
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-35540HIGHwebappsphp10 abr 2025
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or
41RIESGO
abrir
Exploit-DB
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
CVE-2024-6244HIGHwebappsphp09 abr 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RIESGO
abrir
Exploit-DB
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
CVE-2024-27348CRITICALbajo ataquewebappsjava09 abr 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
Exploit-DB
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
CVE-2024-38944CRITICALwebappsmultiple09 abr 2025
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir
Exploit-DBVexDay Proof
DocsGPT 0.12.0 - Remote Code Execution
CVE-2025-0868CRITICALwebappspython09 abr 2025
Remote Code Execution in DocsGPT
68RIESGO
abrir
Exploit-DB
ChurchCRM 5.9.1 - SQL Injection
CVE-2024-39304HIGHwebappsphp09 abr 2025
ChurchCRM SQL Injection Vulnerability
41RIESGO
abrir
Exploit-DB
Artica Proxy 4.50 - Remote Code Execution (RCE)
CVE-2024-2054CRITICALwebappsphp09 abr 2025
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir
Exploit-DB
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
CVE-2024-24409HIGHwebappsmultiple09 abr 2025
Privilege Escalation
41RIESGO
abrir
Exploit-DB
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-39143MEDIUMwebappsphp09 abr 2025
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea
33RIESGO
abrir
Exploit-DB
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
CVE-2024-30896CRITICALremotemultiple08 abr 2025
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RIESGO
abrir
Exploit-DB
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
CVE-2024-23922MEDIUMremotemultiple08 abr 2025
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
33RIESGO
abrir
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2020-7656webappsmultiple08 abr 2025
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RIESGO
abrir
Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
CVE-2019-15949HIGHbajo ataquewebappsmultiple08 abr 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
CVE-2024-56902HIGHwebappsmultiple08 abr 2025
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RIESGO
abrir
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2019-11358webappsmultiple08 abr 2025
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
CVE-2025-24813CRITICALbajo ataquewebappsmultiple07 abr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
CVE-2025-24893CRITICALbajo ataquewebappsmultiple07 abr 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
CVE-2025-31131HIGHwebappsmultiple07 abr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-9458MEDIUMwebappsphp06 abr 2025
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RIESGO
abrir
Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
CVE-2024-8856CRITICALwebappsphp06 abr 2025
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir
Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
CVE-2024-5910CRITICALbajo ataquewebappsmultiple06 abr 2025
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir
Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
CVE-2024-30269MEDIUMwebappsjava06 abr 2025
DataEase has database configuration information exposure vulnerability
53RIESGO
abrir
Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
CVE-2024-48827HIGHwebappsmultiple06 abr 2025
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.