Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
4193 exploits
Nucleicritical
Apache ActiveMQ - Remote Code Execution
CVE-2023-46604CRITICALbajo ataqueransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Nucleimedium
OpenSSH Terrapin Attack - Detection
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
50RIESGO
abrir
Nucleihigh
Jenkins < 2.441 - Arbitrary File Read
CVE-2024-23897CRITICALbajo ataqueransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RIESGO
abrir
Nucleicritical
Zimbra Collaboration Suite < 9.0.0 - Remote Code Execution
CVE-2024-45519CRITICALbajo ataque
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RIESGO
abrir
Nucleihigh
CUPS - Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
Nucleimedium
Citrix NetScaler ADC & Gateway - Reflected XSS / Open Redirect
Cross-Site Scripting (XSS)
33RIESGO
abrir
Nucleihigh
MongoDB Server - Information Disclosure (MongoBleed)
CVE-2025-14847HIGHbajo ataque
Zlib compressed protocol header length confusion may allow memory read
100RIESGO
abrir
Nucleihigh
D-Link DIR-823X set_prohibiting - Command Injection
CVE-2025-29635HIGHbajo ataque
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrar
88RIESGO
abrir
Nucleicritical
Redis < 8.2.1 lua script - Integer Overflow
Lua library commands may lead to integer overflow and potential RCE
36RIESGO
abrir
Nucleihigh
Redis Lua Sandbox < 8.2.2 - Cross-User Escape
Redis: Authenticated users can execute LUA scripts as a different user
28RIESGO
abrir
Nucleihigh
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read
Redis is vulnerable to DoS via specially crafted LUA scripts
28RIESGO
abrir
Nucleicritical
Redis Lua Parser < 8.2.2 - Use After Free
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
Nucleicritical
Palo Alto Networks PAN-OS - Authentication Bypass
CVE-2026-0257HIGHbajo ataque
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RIESGO
abrir
Nucleicritical
BeyondTrust Remote Support - Unauthenticated WebSocket RCE
CVE-2026-1731CRITICALbajo ataqueransomware
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
Nucleicritical
Apache Camel camel-coap - Remote Code Execution
Apache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
63RIESGO
abrir
Nucleihigh
Vite Dev Server - Arbitrary File Read
Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
36RIESGO
abrir
Nucleicritical
Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE
CVE-2026-39987CRITICALbajo ataque
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
Nucleihigh
Next.js WebSocket Upgrade Handler - SSRF
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RIESGO
abrir
Nucleicritical
Samba Printing Subsystem - Remote Code Execution
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RIESGO
abrir
Nucleimedium
OpenVPN Access Server 2.1.4 - CRLF Injection
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbit
18RIESGO
abrir
Nucleimedium
Odoo <= 8.0-20160726 & 9.0 - Open Redirect
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive in
18RIESGO
abrir
Nucleihigh
Kodi 17.1 - Local File Inclusion
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir
Nucleicritical
JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer,
23RIESGO
abrir
Nucleihigh
PhpColl 2.5.1 Arbitrary File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
Nucleimedium
MaNGOSWebV4 < 4.0.8 - Cross-Site Scripting
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RIESGO
abrir
Nucleicritical
Windows Server 2003 & IIS 6.0 - Remote Code Execution
CVE-2017-7269CRITICALbajo ataque
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Nucleimedium
Magmi 0.7.22 - Cross-Site Scripting
A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration o
18RIESGO
abrir
Nucleihigh
MantisBT <=2.30 - Arbitrary Password Reset/Admin Access
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
Nucleimedium
IceWarp WebMail 11.3.1.5 - Cross-Site Scripting
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" paramet
18RIESGO
abrir
Nucleicritical
Hikvision - Authentication Bypass
CVE-2017-7921CRITICALbajo ataque
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.