Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
76.008 exploits
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALbajo ataque13 feb 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware12 feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque12 feb 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
CVE-2021-43798HIGHbajo ataque12 feb 2025
Grafana path traversal
100RIESGO
abrir
GitHub PoC
An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the URL which leads to path traversal to any file that exists in the system. Nostromo’s versions such as 1.9.6 fail to verify this URL
CVE-2019-16278CRITICALbajo ataque12 feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
qnole000/CVE-2024-51378
CVE-2024-51378CRITICALbajo ataqueransomware12 feb 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RIESGO
abrir
Metasploit300
Audiobookshelf Unauthenticated API Authentication Bypass Scanner
CVE-2025-25205HIGH12 feb 2025
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
36RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque12 feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134
CVE-2022-26134CRITICALbajo ataqueransomware12 feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
Alienfader/CVE-2020-29607
CVE-2020-2960711 feb 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir
GitHub PoC1
Exploit for Apache OFBiz - CVE-2024-38856
CVE-2024-38856HIGHbajo ataque11 feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
GitHub PoC2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
CVE-2024-53704HIGHbajo ataqueransomware11 feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
GitHub PoC4
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.
CVE-2024-42009CRITICALbajo ataque11 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
GitHub PoC1
yenyangmjaze/cve-2024-10914
CVE-2024-10914CRITICAL11 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-38856HIGHbajo ataque11 feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53704HIGHbajo ataqueransomware11 feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALbajo ataque11 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALbajo ataque10 feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALbajo ataque10 feb 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 feb 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RIESGO
abrir
GitHub PoC1
cve-2019-5420 POC simple ruby script
CVE-2019-542010 feb 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
CVE-2022-40684CRITICALbajo ataqueransomware10 feb 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
Metasploit600
Wazuh server remote code execution caused by an unsafe deserialization vulnerability.
CVE-2025-24016CRITICALbajo ataque10 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
CVE-2024-27348CRITICALbajo ataque10 feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir
GitHub PoC
RogelioPumajulca/CVE-2022-0847
CVE-2022-0847HIGHbajo ataque09 feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
0x7556/CVE-2024-55591
CVE-2024-55591CRITICALbajo ataqueransomware09 feb 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RIESGO
abrir
GitHub PoC
skrkcb2/CVE-2024-5452
CVE-2024-5452CRITICAL09 feb 2025
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-0847HIGHbajo ataque09 feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
anteriorpágina 303 / 2534siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.