Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
8150 exploits
VulnCheck XDB
infoleak
CVE-2024-51977MEDIUM22 may 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9463CRITICALbajo ataque22 may 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALbajo ataqueransomware22 may 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-4322CRITICAL21 may 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHbajo ataque21 may 2025
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware21 may 2025
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALbajo ataqueransomware21 may 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque21 may 2025
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMbajo ataqueransomware21 may 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL20 may 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque19 may 2025
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2021-38003HIGHbajo ataque19 may 2025
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMbajo ataque19 may 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALbajo ataque18 may 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALbajo ataqueransomware18 may 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RIESGO
abrir
VulnCheck XDB
local
CVE-2024-44258HIGH18 may 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RIESGO
abrir
VulnCheck XDB
local
CVE-2025-0288HIGH17 may 2025
CVE-2025-0288
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-47539CRITICAL17 may 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque16 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-4428HIGHbajo ataque16 may 2025
Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-3605CRITICAL15 may 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque15 may 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALbajo ataque15 may 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-4428HIGHbajo ataque15 may 2025
Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-4427MEDIUMbajo ataque15 may 2025
Authentication Bypass
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM14 may 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RIESGO
abrir
VulnCheck XDB
local
CVE-2025-29824HIGHbajo ataqueransomware14 may 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque14 may 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque14 may 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque13 may 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.