Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
82.081 exploits
Exploit-DB✓ VexDay Proof
Dream Poll 3.1 - '/index.php' Cross-Site Scripting / SQL Injection
CVE-2009-4745—webappsphp13 oct 2009
Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EZRecipeZee CMS 91 - Remote File Inclusion
CVE-2009-3694—webappsphp12 oct 2009
Directory traversal vulnerability in config/config.php in ezRecipe-Zee 91, when register_globals is enabled, allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Docebo 3.6.0.3 - Multiple SQL Injections
CVE-2009-4742—webappsphp09 oct 2009
Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
httpdx 1.4.5 - dot Character Remote File Disclosure
CVE-2009-4531—remotewindows09 oct 2009
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) charact
23RIESGO
abrir ↗
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHbajo ataque08 oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
httpdx 1.4 - GET Buffer Overflow
CVE-2009-3711—remotewindows08 oct 2009
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RIESGO
abrir ↗
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHbajo ataque08 oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DreamPoll 3.1 - SQL Injection
CVE-2009-4746—webappsphp08 oct 2009
Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 6.4 - 'pipeclose()'/'knlist_cleardel()' Race Condition
CVE-2009-3527—localfreebsd08 oct 2009
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (
23RIESGO
abrir ↗
Metasploit500
HTTPDX h_handlepeer() Function Buffer Overflow
CVE-2009-3711—08 oct 2009
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DreamPoll 3.1 - SQL Injection
CVE-2009-4745—webappsphp08 oct 2009
Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Riorey RIOS 4.7.0 - Hard-Coded Password
CVE-2009-3710—remotehardware08 oct 2009
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VMware Player / VMware Workstation 6.5.3 - 'VMware-authd' Remote Denial of Service
CVE-2009-3707—doswindows07 oct 2009
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 befor
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BulletProof FTP Client 2.63 b56 - '.bps' File Stack Buffer Overflow
CVE-2008-5754—remotewindows07 oct 2009
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir ↗
Metasploit500
AIX Calendar Manager Service Daemon (rpc.cmsd) Opcode 21 Buffer Overflow
CVE-2009-3699—07 oct 2009
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP LaserJet Printers - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2009-2684—remotehardware07 oct 2009
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJe
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AIOCP 1.4.001 - Remote File Inclusion
CVE-2009-4747—webappsphp07 oct 2009
PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.00
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AfterLogic WebMail Pro 4.7.10 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-4743—webappsasp06 oct 2009
Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
X-Cart Email Subscription - 'email' Cross-Site Scripting
CVE-2009-3592—webappsphp06 oct 2009
Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
e-Courier CMS - 'UserGUID' Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-3901—webappsasp06 oct 2009
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dopewars Server 1.5.12 - Denial of Service
CVE-2009-3591—dosmultiple06 oct 2009
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RIESGO
abrir ↗
Metasploit300
Dopewars Denial of Service
CVE-2009-3591—05 oct 2009
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alleycode 2.21 - Local Overflow (SEH)
CVE-2009-3709—localwindows05 oct 2009
Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Informix Client SDK 3.0 - '.nfx' File Integer Overflow
CVE-2009-3691—remotewindows05 oct 2009
Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Run
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Empire CMS 47 - SQL Injection
CVE-2009-2269—webappsphp05 oct 2009
SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid para
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component CB Resume Builder - SQL Injection
CVE-2009-3645—webappsphp05 oct 2009
SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AfterLogic WebMail Pro 4.7.10 - Cross-Site Scripting
CVE-2009-4743—webappsasp05 oct 2009
Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Soundset 1.0 - SQL Injection
CVE-2009-3644—webappsphp05 oct 2009
SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alleycode 2.21 - Local Overflow (SEH)
CVE-2009-3708—localwindows05 oct 2009
Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-a
23RIESGO
abrir ↗
Metasploit300
NTP.org ntpd Reserved Mode Denial of Service
CVE-2009-3563—04 oct 2009
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba
30RIESGO
abrir ↗
← anteriorpágina 1341 / 2737siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.