Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
8156 exploits
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL21 feb 2025
WAGO: WBM Command Injection in multiple products
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH20 feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALbajo ataque20 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque19 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2025-0411HIGHbajo ataque19 feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHbajo ataque19 feb 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2024-13159CRITICALbajo ataque18 feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque18 feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2023-4911HIGHbajo ataque18 feb 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque18 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL17 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALbajo ataque17 feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1881816 feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALbajo ataque16 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2025-0108HIGHbajo ataque14 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware14 feb 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-21551HIGHbajo ataque13 feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-0108HIGHbajo ataque13 feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALbajo ataque13 feb 2025
Remote code execution in Wazuh server
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2024-42009CRITICALbajo ataque13 feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque12 feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque12 feb 2025
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware12 feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.