Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
8150 exploits
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM06 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-14871CRITICALbajo ataque06 jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALbajo ataqueransomware06 jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALbajo ataqueransomware06 jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALbajo ataque05 jun 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-46604HIGH05 jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALbajo ataque05 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALbajo ataque05 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-2539HIGH04 jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque04 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-20085HIGHbajo ataque04 jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999502 jun 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALbajo ataque02 jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-25690CRITICAL01 jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL31 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-30397HIGHbajo ataque31 may 2025
Scripting Engine Memory Corruption Vulnerability
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALbajo ataqueransomware31 may 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-5287HIGH31 may 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-7399HIGHbajo ataque30 may 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-26828HIGHbajo ataque30 may 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2291129 may 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 may 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL29 may 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 may 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware28 may 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.