Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
formmail 1.92 - Multiple Vulnerabilities
CVE-2009-1777webappsphp15 jun 2009
CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Netgear DG632 Router - Authentication Bypass
CVE-2009-2257remotehardware15 jun 2009
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 11.1 - Database Network Foundation Heap Memory Corruption
CVE-2009-1963dosmultiple14 jun 2009
Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated us
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic Server 10.3 - 'console-help.portal' Cross-Site Scripting
CVE-2009-1975remotemultiple14 jun 2009
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect c
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - TNS Command Remote Denial of Service
CVE-2009-1970dosmultiple14 jun 2009
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.
28RIESGO
abrir
Exploit-DBVexDay Proof
Scriptsez Easy Image Downloader - 'id' Cross-Site Scripting
CVE-2009-2551webappsphp14 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - Remote Network Authentication
CVE-2009-1019remotemultiple14 jun 2009
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - Network Foundation Remote Overflow
CVE-2009-1020remotemultiple14 jun 2009
Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4,
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g Secure Enterprise Search - 'search_p_groups' Cross-Site Scripting
CVE-2009-1968remotemultiple14 jun 2009
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
HP ProCurve Threat Management Services - zl ST.1.0.090213 Module CRL Security Bypass
CVE-2009-1422remotemultiple13 jun 2009
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows
23RIESGO
abrir
Exploit-DBVexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2132webappsphp12 jun 2009
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
School Data Navigator - 'page' Local/Remote File Inclusion
CVE-2009-2641webappsphp10 jun 2009
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-2642webappsphp10 jun 2009
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
CVE-2009-2633webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
CVE-2009-2634webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
CVE-2009-2637webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
CVE-2009-2635webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
CVE-2009-2638webappsphp09 jun 2009
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
CVE-2009-2639webappsphp09 jun 2009
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Cached Content Cross Domain Information Disclosure
CVE-2009-1140remotewindows09 jun 2009
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vist
28RIESGO
abrir
Exploit-DBVexDay Proof
Computer Associates SiteMinder - Unicode Cross-Site Scripting Protection Security Bypass
CVE-2009-2705webappsjava08 jun 2009
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RIESGO
abrir
Exploit-DBVexDay Proof
Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download
CVE-2009-2386remotemultiple08 jun 2009
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions
23RIESGO
abrir
Exploit-DBVexDay Proof
Interlogy Profile Manager Basic - Insecure Cookie Handling
CVE-2009-2640webappscgi08 jun 2009
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Computer Associates SiteMinder - '%00' Cross-Site Scripting Protection Security Bypass
CVE-2009-2704webappsphp08 jun 2009
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 5.0.75 - 'sql_parse.cc' Multiple Format String Vulnerabilities
CVE-2009-2446doslinux08 jun 2009
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0
28RIESGO
abrir
Exploit-DBVexDay Proof
ClanSphere 2009 - 'text' Cross-Site Scripting
CVE-2009-2438webappsphp06 jun 2009
Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Avax Vector 1.3 - 'avPreview.ocx' ActiveX Control Buffer Overflow
CVE-2009-2377remotewindows06 jun 2009
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde 3.1 - 'Passwd' Module Cross-Site Scripting
CVE-2009-2360webappsphp05 jun 2009
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
PeaZIP 2.6.1 - Compressed Filename Command Injection
CVE-2009-2261localwindows05 jun 2009
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RIESGO
abrir
Exploit-DBVexDay Proof
Online Armor < 3.5.0.12 - 'OAmon.sys' Local Privilege Escalation
CVE-2009-2450localwindows04 jun 2009
The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Pers
23RIESGO
abrir
anteriorpágina 265 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.