Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
8722 exploits
VulnCheck XDB
initial-access
CVE-2026-35616CRITICALbajo ataque19 abr 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-15030CRITICAL18 abr 2026
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-2563HIGH18 abr 2026
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-27542CRITICAL18 abr 2026
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALbajo ataque18 abr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-4631CRITICAL18 abr 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RIESGO
abrir
VulnCheck XDB
client-side
CVE-2026-25253HIGH18 abr 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39808CRITICALbajo ataque18 abr 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-13342CRITICAL18 abr 2026
Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1492CRITICAL18 abr 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM17 abr 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL17 abr 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL17 abr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-26980CRITICAL17 abr 2026
Ghost has a SQL Injection in its Content API
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-33032CRITICAL17 abr 2026
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-8110HIGHbajo ataque17 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque17 abr 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL16 abr 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-42009CRITICALbajo ataque16 abr 2026
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-30088HIGHbajo ataqueransomware16 abr 2026
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49113CRITICALbajo ataque16 abr 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque16 abr 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL16 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL15 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
local
CVE-2024-26229HIGH15 abr 2026
Windows CSC Service Elevation of Privilege Vulnerability
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-39808CRITICALbajo ataque15 abr 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHbajo ataque15 abr 2026
File overwrite in file update API in Gogs
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL15 abr 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL15 abr 2026
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-21413CRITICALbajo ataque14 abr 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.