Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
CVE-2009-0527webappsphp
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
IF-CMS 2.0 - 'id' Blind SQL Injection
CVE-2009-0528webappsphp
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-0529webappsphp
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to i
23RIESGO
abrir
ReferênciaVexDay Proof
A Better Member-Based ASP Photo Gallery - 'entry' SQL Injection
CVE-2009-0531webappsphp
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
FlexCMS 2.5 - 'catId' SQL Injection
CVE-2009-0534webappsphp
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter
23RIESGO
abrir
ReferênciaVexDay Proof
Mailist 3.0 - Insecure Backup / Local File Inclusion
CVE-2009-0570webappsphp
Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_q
23RIESGO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
CVE-2009-0592webappsphp
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RIESGO
abrir
ReferênciaVexDay Proof
SquirrelMail G/PGP Encryption Plugin 2.0 - Command Execution
CVE-2005-1924webappsphp
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands v
28RIESGO
abrir
ReferênciaVexDay Proof
Multiple Vendor - PF Null Pointer Dereference
CVE-2009-0687dosbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RIESGO
abrir
ReferênciaVexDay Proof
OpenBSD 4.5 - IP datagrams Remote Denial of Service
CVE-2009-0687dosopenbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RIESGO
abrir
ReferênciaVexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
CVE-2009-0866webappsphp
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
CVE-2009-0879doswindows
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir
ReferênciaVexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
CVE-2009-0885doswindows
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir
ReferênciaVexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
CVE-2009-0886webappsphp
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RIESGO
abrir
ReferênciaVexDay Proof
Apple iTunes 8.1.1 - 'ITMS' Multiple Protocol Handler Buffer Overflow (Metasploit)
CVE-2009-0950remoteosx
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir
ReferênciaVexDay Proof
Apple iTunes 8.1.1.10 (Windows) - 'itms/itcp' Remote Buffer Overflow
CVE-2009-0950remotewindows
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir
ReferênciaVexDay Proof
GDL 4.x - 'node' SQL Injection
CVE-2009-0965webappsphp
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
CVE-2009-0968webappsphp
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
CVE-2009-1022doswindows
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1024webappsphp
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1025webappsphp
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute
28RIESGO
abrir
ReferênciaVexDay Proof
Kim Websites 1.0 - Authentication Bypass
CVE-2009-1026webappsphp
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1028doswindows
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RIESGO
abrir
ReferênciaVexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RIESGO
abrir
ReferênciaVexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
CVE-2009-1041localfreebsd
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RIESGO
abrir
ReferênciaVexDay Proof
Bloginator 1a - SQL Injection / Command Injection (via Cookie Bypass )
CVE-2009-1049webappsphp
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
eXeScope 6.50 - Local Buffer Overflow
CVE-2009-1063localwindows
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RIESGO
abrir
ReferênciaVexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
CVE-2009-1071localwindows
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RIESGO
abrir
ReferênciaVexDay Proof
PPLive 1.9.21 - '/LoadModule' URI Handlers Argument Injection
CVE-2009-1087remotewindows
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute
23RIESGO
abrir
anteriorpágina 146 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.