Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Cisco ASA Appliance 8.x - WebVPN DOM Wrapper Cross-Site Scripting
CVE-2009-1201remotehardware24 may 2009
Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Ap
23RIESGO
abrir
Exploit-DBVexDay Proof
Tutorial Share 3.5.0 - Insecure Cookie Handling
CVE-2009-2293webappsphp22 may 2009
Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administ
23RIESGO
abrir
Exploit-DBVexDay Proof
Mole Group Sky Hunter/Bus Ticket Scripts - Change Admin Password
CVE-2009-4674webappsphp22 may 2009
admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to cha
23RIESGO
abrir
Exploit-DBVexDay Proof
Nagios 3.0.6 - 'statuswml.cgi' Arbitrary Shell Command Injection
CVE-2009-2288remotecgi22 may 2009
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RIESGO
abrir
Exploit-DBVexDay Proof
Mole Group Restaurant Directory Script 3.0 - Change Admin Password
CVE-2009-4675webappsphp22 may 2009
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative
23RIESGO
abrir
Exploit-DBVexDay Proof
asp inline Corporate Calendar - SQL Injection / Cross-Site Scripting
CVE-2009-2241webappsasp21 may 2009
Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to injec
23RIESGO
abrir
Exploit-DBVexDay Proof
Article Directory - Authentication Bypass
CVE-2009-2236webappsphp21 may 2009
SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Article Directory - 'page.php' Blind SQL Injection
CVE-2009-2235webappsphp21 may 2009
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Groupwise 8.0 Webaccess - Multiple Vulnerabilities
CVE-2009-1634remotemultiple21 may 2009
The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement sessi
23RIESGO
abrir
Exploit-DBVexDay Proof
BaoFeng - 'config.dll' ActiveX Remote Code Execution
CVE-2009-1807remotewindows21 may 2009
Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIDIAL 2.0.5-173 - Authentication Bypass
CVE-2009-2234webappsphp21 may 2009
Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
ChinaGames - 'CGAgent.dll' ActiveX Remote Code Execution
CVE-2009-1800remotewindows21 may 2009
Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames i
28RIESGO
abrir
Exploit-DBVexDay Proof
Flash Quiz Beta 2 - Multiple SQL Injections
CVE-2009-1843webappsphp21 may 2009
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
asp inline Corporate Calendar - SQL Injection / Cross-Site Scripting
CVE-2009-2242webappsasp21 may 2009
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
asp inline Corporate Calendar - SQL Injection / Cross-Site Scripting
CVE-2009-2243webappsasp21 may 2009
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF 3.8.2 - 'LZWDecodeCompat()' Remote Buffer Underflow
CVE-2009-2285doslinux21 may 2009
Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial o
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Java applet Remote Deserialization Remote (2)
CVE-2008-5353remoteosx20 may 2009
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RIESGO
abrir
Exploit-DBVexDay Proof
Profense 2.2.20/2.4.2 - Web Application Firewall Security Bypass
CVE-2009-1593webappsphp20 may 2009
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "neg
23RIESGO
abrir
Exploit-DBVexDay Proof
Kingsoft Webshield 1.1.0.62 - Cross-Site Scripting / Remote Command Execution
CVE-2009-1786webappsphp20 may 2009
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a syml
23RIESGO
abrir
Exploit-DBVexDay Proof
DMXReady Registration Manager 1.1 - Arbitrary File Upload
CVE-2009-2238webappsasp20 may 2009
Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXRea
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Communications Express 6.3 - 'search.xml' Cross-Site Scripting
CVE-2009-1729webappsjava20 may 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Communications Express 6.3 - 'UWCMain' Cross-Site Scripting
CVE-2009-1729webappsjava20 may 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Casino 0.3.1 - Multiple SQL Injections s
CVE-2009-2239webappsphp20 may 2009
SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3)
23RIESGO
abrir
Exploit-DBVexDay Proof
DirectAdmin 1.33.6 - 'CMD_REDIRECT' Cross-Site Scripting
CVE-2009-2216webappsjava19 may 2009
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'parent/top' Cross Domain Scripting
CVE-2009-1724remotemultiple19 may 2009
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone
23RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.3.5 - Format String / Security Bypass
CVE-2009-1886remotelinux19 may 2009
Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL 0.9.8k/1.0.0-beta2 - DTLS Remote Memory Exhaustion Denial of Service
CVE-2009-1379dosmultiple18 may 2009
Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 a
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (3)
CVE-2009-0961remotehardware17 may 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (1)
CVE-2009-0961remotehardware17 may 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (2)
CVE-2009-0961remotehardware17 may 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RIESGO
abrir
anteriorpágina 268 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.