Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
82.117 exploits
Exploit-DB✓ VexDay Proof
phpMyAdmin - 'pmaPWN!' Code Injection / Remote Code Execution
CVE-2009-1151CRITICALbajo ataquewebappsphp22 jun 2009
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir ↗
Metasploit600
Nagios3 statuswml.cgi Ping Command Execution
CVE-2009-2288—22 jun 2009
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyBB 1.4.6 - Remote Code Execution
CVE-2009-2230—webappsphp22 jun 2009
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Bopup Communications Server 3.2.26.5460 - Remote SYSTEM
CVE-2009-2227—remotewindows22 jun 2009
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kasseler CMS - File Disclosure / Cross-Site Scripting
CVE-2009-2228—webappsphp22 jun 2009
Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kasseler CMS - File Disclosure / Cross-Site Scripting
CVE-2009-2229—webappsphp22 jun 2009
Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.0.11 and Thunderbird 2.0.9 - RDF File Handling Remote Memory Corruption
CVE-2009-2464—doslinux21 jun 2009
The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Programs Rating - 'rate.php?id' Cross-Site Scripting
CVE-2009-4690—webappsphp20 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Programs Rating - 'postcomments.php?id' Cross-Site Scripting
CVE-2009-4690—webappsphp20 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Edraw PDF Viewer Component < 3.2.0.126 - ActiveX Insecure Method
CVE-2009-2169—remotewindows18 jun 2009
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Compo
23RIESGO
abrir ↗
Metasploit400
Bopup Communications Server Buffer Overflow
CVE-2009-2227—18 jun 2009
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DESlock+ 4.0.2 - 'dlpcrypt.sys' Local Kernel Ring0 Code Execution
CVE-2009-4832—localwindows18 jun 2009
The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80
23RIESGO
abrir ↗
Metasploit500
ToolTalk rpc.ttdbserverd _tt_internal_realpath Buffer Overflow (AIX)
CVE-2009-2727—17 jun 2009
Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Compface 1.5.2 - '.xbm' Local Buffer Overflow (PoC)
CVE-2009-2286—doslinux17 jun 2009
Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iDefense COMRaider - ActiveX Control Multiple Insecure Method Vulnerabilities
CVE-2009-3860—remotewindows17 jun 2009
Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitr
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-17382—17 jun 2009
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build
23RIESGO
abrir ↗
Metasploit300
Slowloris Denial of Service Attack
CVE-2010-2227—17 jun 2009
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-En
30RIESGO
abrir ↗
Metasploit300
Slowloris Denial of Service Attack
CVE-2007-6750—17 jun 2009
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP
40RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-12373—17 jun 2009
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1000385—17 jun 2009
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. Thi
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-6168—17 jun 2009
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (f
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-17427—17 jun 2009
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2012-5081—17 jun 2009
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
30RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-13098HIGH17 jun 2009
BouncyCastle JCE TLS Bleichenbacher/ROBOT
41RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-17428—17 jun 2009
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS cip
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2016-6883—17 jun 2009
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a B
23RIESGO
abrir ↗
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-13099HIGH17 jun 2009
wolfSSL Bleichenbacher/ROBOT
41RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.30 - 'tun_chr_pool()' Null Pointer Dereference
CVE-2009-1897—doslinux17 jun 2009
The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -f
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netgear DG632 Router - Authentication Bypass
CVE-2009-2257—remotehardware15 jun 2009
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netgear DG632 Router - Remote Denial of Service
CVE-2009-2256—doshardware15 jun 2009
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o
23RIESGO
abrir ↗
← anteriorpágina 1369 / 2738siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.