Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
8156 exploits
VulnCheck XDB
initial-access
CVE-2024-53704HIGHbajo ataqueransomware11 feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque11 feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALbajo ataque11 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALbajo ataque10 feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 feb 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-0847HIGHbajo ataque09 feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque08 feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 feb 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-30190HIGHbajo ataqueransomware07 feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware06 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHbajo ataque06 feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMbajo ataqueransomware06 feb 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL05 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 feb 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-24919HIGHbajo ataqueransomware05 feb 2025
Information disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH04 feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-370402 feb 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH02 feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALbajo ataqueransomware02 feb 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware02 feb 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL02 feb 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware02 feb 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-023231 ene 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware30 ene 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware30 ene 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 ene 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-32315HIGHbajo ataque30 ene 2025
Openfire administration console authentication bypass
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHbajo ataque30 ene 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.