Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
8156 exploits
VulnCheck XDB
infoleak
CVE-2025-282504 abr 2025
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL04 abr 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-38163CRITICALbajo ataque04 abr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 abr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 abr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-282503 abr 2025
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL03 abr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM03 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-44026CRITICALbajo ataque02 abr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394202 abr 2025
Remote Code Execution in Apache Unomi
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919302 abr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 abr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM02 abr 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMbajo ataque01 abr 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALbajo ataque01 abr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALbajo ataqueransomware01 abr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4220HIGH01 abr 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL31 mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM31 mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque31 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH31 mar 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL31 mar 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-36991HIGH30 mar 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL30 mar 2025
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2012-486930 mar 2025
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-4587830 mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque30 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque30 mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque30 mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.