Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
8843 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware11 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-29059MEDIUM11 ene 2026
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
48RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque11 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware10 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque09 ene 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-23397CRITICALbajo ataque09 ene 2026
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque09 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALbajo ataqueransomware08 ene 2026
Upload Arbitrary Files
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque08 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-54068CRITICALbajo ataque08 ene 2026
Livewire vulnerable to remote command execution during property update hydration
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque07 ene 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALbajo ataque07 ene 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RIESGO
abrir
VulnCheck XDB
local
CVE-2025-32463CRITICALbajo ataque07 ene 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque07 ene 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL07 ene 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque07 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware06 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware06 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-37164CRITICALbajo ataque06 ene 2026
A remote code execution issue exists in HPE OneView.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALbajo ataqueransomware06 ene 2026
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2025-14847HIGHbajo ataque06 ene 2026
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL06 ene 2026
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware06 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-43529HIGHbajo ataque05 ene 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-14998CRITICAL05 ene 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware05 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware05 ene 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque05 ene 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2011HIGH05 ene 2026
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13390CRITICAL05 ene 2026
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.