Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
8843 exploits
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALbajo ataque22 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32463CRITICALbajo ataque22 feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHbajo ataque21 feb 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-68645HIGHbajo ataque21 feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL21 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
local
CVE-2022-37969HIGHbajo ataque20 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware20 feb 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2026-1405CRITICAL20 feb 2026
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALbajo ataque19 feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-24521HIGHbajo ataqueransomware19 feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALbajo ataque19 feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque19 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque19 feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2026-2441HIGHbajo ataque19 feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-71243CRITICAL19 feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 feb 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-919418 feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALbajo ataque18 feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALbajo ataqueransomware18 feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-47812CRITICALbajo ataque18 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque17 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALbajo ataque17 feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque17 feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALbajo ataqueransomware17 feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL16 feb 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49132CRITICAL16 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL15 feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-7921CRITICALbajo ataque15 feb 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALbajo ataque15 feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.