Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.459 exploits
Exploit-DB
Sudo chroot 1.9.17 - Local Privilege Escalation
CVE-2025-32463CRITICALbajo ataquelocallinux08 jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir
Exploit-DB
Discourse 3.2.x - Anonymous Cache Poisoning
CVE-2024-47773HIGHwebappsmultiple08 jul 2025
Anonymous cache poisoning via XHR requests in Discourse
41RIESGO
abrir
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege
CVE-2025-32462LOWlocallinux08 jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RIESGO
abrir
Exploit-DB
Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICALwebappsmultiple08 jul 2025
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RIESGO
abrir
Exploit-DB
Microsoft Outlook - Remote Code Execution (RCE)
CVE-2025-47171MEDIUMremotewindows08 jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
33RIESGO
abrir
Exploit-DB
Microsoft Defender for Endpoint (MDE) - Elevation of Privilege
CVE-2025-47161HIGHlocalmultiple08 jul 2025
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
CVE-2025-47812CRITICALbajo ataqueremotemultiple02 jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Exploit-DB
gogs 0.13.0 - Remote Code Execution (RCE)
CVE-2024-39930CRITICALremotemultiple02 jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RIESGO
abrir
Exploit-DB
Moodle 4.4.0 - Authenticated Remote Code Execution
CVE-2024-43425HIGHwebappsmultiple02 jul 2025
Moodle: remote code execution via calculated question types
78RIESGO
abrir
Exploit-DB
Microsoft SharePoint 2019 - NTLM Authentication
CVE-2025-47166HIGHremotewindows02 jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
46RIESGO
abrir
Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
CVE-2019-9978MEDIUMbajo ataquewebappsmultiple26 jun 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
CVE-2025-27218MEDIUMwebappsmultiple26 jun 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RIESGO
abrir
Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
CVE-2025-47165HIGHremotewindows26 jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RIESGO
abrir
Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
CVE-2025-49132CRITICALwebappsmultiple26 jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RIESGO
abrir
Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
CVE-2025-5640MEDIUMremotemultiple26 jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RIESGO
abrir
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 jun 2025
freeSSHd denial of service
33RIESGO
abrir
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RIESGO
abrir
Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
CVE-2022-1257MEDIUMremotemultiple26 jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RIESGO
abrir
Exploit-DB
FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
CVE-2024-50562MEDIUMremotemultiple20 jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RIESGO
abrir
Exploit-DBVexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
CVE-2025-1974CRITICALremotemultiple20 jun 2025
ingress-nginx admission controller RCE escalation
85RIESGO
abrir
Exploit-DB
Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
CVE-2025-47957HIGHlocalwindows20 jun 2025
Microsoft Word Remote Code Execution Vulnerability
41RIESGO
abrir
Exploit-DB
Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)
CVE-2025-33073HIGHbajo ataqueremotewindows15 jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RIESGO
abrir
Exploit-DB
Microsoft Excel Use After Free - Local Code Execution
CVE-2025-27751HIGHlocalwindows15 jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RIESGO
abrir
Exploit-DB
Parrot and DJI variants Drone OSes - Kernel Panic Exploit
CVE-2025-37928localmultiple15 jun 2025
dm-bufio: don't schedule in atomic context
23RIESGO
abrir
Exploit-DB
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
CVE-2025-46041MEDIUMwebappsphp15 jun 2025
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript
33RIESGO
abrir
Exploit-DB
PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
CVE-2024-4577CRITICALbajo ataqueransomwarewebappsphp15 jun 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
Exploit-DB
PCMan FTP Server 2.0.7 - Buffer Overflow
CVE-2025-4255MEDIUMremotewindows15 jun 2025
PCMan FTP Server RMD Command buffer overflow
33RIESGO
abrir
Exploit-DB
Roundcube 1.6.10 - Remote Code Execution (RCE)
CVE-2025-49113CRITICALbajo ataquewebappsmultiple13 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
Exploit-DB
Freefloat FTP Server 1.0 - Remote Buffer Overflow
CVE-2025-5548MEDIUMremotemultiple13 jun 2025
FreeFloat FTP Server NOOP Command buffer overflow
38RIESGO
abrir
Exploit-DB
Windows File Explorer Windows 10 Pro x64 - TAR Extraction
CVE-2025-24071MEDIUMremotewindows13 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.