Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Mercury Audio Player 1.21 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-4754doswindows30 abr 2009
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercury Audio Player 1.21 - '.b4s' Local Stack Overflow
CVE-2009-4755localwindows30 abr 2009
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via
23RIESGO
abrir
Exploit-DBVexDay Proof
GnuTLS 2.6.x - libgnutls lib/pk-libgcrypt.c Malformed DSA Key Handling Remote Denial of Service
CVE-2009-1415doslinux30 abr 2009
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
GnuTLS 2.6.x - libgnutls lib/gnutls_pk.c DSA Key Storage Remote Spoofing
CVE-2009-1416remotelinux30 abr 2009
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the i
23RIESGO
abrir
Exploit-DBVexDay Proof
mpegable Player 2.12 - '.yuv' Local Stack Overflow (PoC)
CVE-2009-4758doswindows29 abr 2009
Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (applicat
23RIESGO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.21 - 'css' Cross-Site Scripting
CVE-2009-1616webappsphp29 abr 2009
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Fax Viewer Control 10 - 'DCCFAXVW.dll' Remote Buffer Overflow
CVE-2009-2570remotewindows29 abr 2009
Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax
28RIESGO
abrir
Exploit-DBVexDay Proof
MIM: InfiniX 1.2.003 - Multiple SQL Injections
CVE-2009-2451webappsphp28 abr 2009
Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec (Multiple Products) - Intel Common Base Agent Remote Command Execution
CVE-2009-1429remotewindows28 abr 2009
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Cente
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20/2.6.24/2.6.27_7-10 (Ubuntu 7.04/8.04/8.10 / Fedora Core 10 / OpenSuse 11.1) - SCTP FWD Memory Corruption Remote Overflow
CVE-2009-0065remotelinux28 abr 2009
Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linu
28RIESGO
abrir
Exploit-DBVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (2)
CVE-2009-1627localwindows27 abr 2009
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
MataChat - 'input.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-1620webappsphp27 abr 2009
Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
libvirt_proxy 0.5.1 - Local Privilege Escalation
CVE-2009-0036locallinux27 abr 2009
Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 3.0.9 - 'nsTextFrame::ClearTextRun()' Remote Memory Corruption
CVE-2009-1313doslinux27 abr 2009
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Linksys WVC54GCA 1.00R22/1.00R24 (Wireless-G) - Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-1557remotehardware25 abr 2009
Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.
23RIESGO
abrir
Exploit-DBVexDay Proof
Linksys WVC54GCA 1.00R22/1.00R24 (Wireless-G) - 'adm/file.cgi' Multiple Directory Traversal Vulnerabilities
CVE-2009-1558remotehardware23 abr 2009
Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00
43RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla (Multiple Products) - Server Refresh Header Cross-Site Scripting
CVE-2009-1312remotelinux22 abr 2009
Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, wh
23RIESGO
abrir
Exploit-DBVexDay Proof
DirectAdmin 1.33.3 - '/CMD_DB' Backup Action Insecure Temporary File Creation
CVE-2009-1526locallinux22 abr 2009
JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle RDBms 10.2.0.3/11.1.0.6 - TNS Listener (PoC)
CVE-2009-0991doswindows21 abr 2009
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 8.0 Client - Denial of Service
CVE-2009-1435doswindows21 abr 2009
NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of servic
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Delegated Administrator 6.x - HTTP Response Splitting
CVE-2009-1357webappsjava21 abr 2009
CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
VS PANEL 7.3.6 - 'Cat_ID' SQL Injection
CVE-2009-3590webappsphp21 abr 2009
SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Contact Manager 3.0 - 'email.php?id' Cross-Site Scripting
CVE-2009-4926webappsphp20 abr 2009
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Photo Pro 2.0 - 'section' Cross-Site Scripting
CVE-2009-4934webappsphp20 abr 2009
Cross-site scripting (XSS) vulnerability in index.php in Online Photo Pro 2.0 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
WB News 2.1.2 - Insecure Cookie Handling
CVE-2009-4927webappsphp20 abr 2009
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cook
23RIESGO
abrir
Exploit-DBVexDay Proof
EZ Webitor - Authentication Bypass
CVE-2009-4933webappsphp20 abr 2009
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
TotalCalendar 2.4 - Remote Password Change
CVE-2009-4929webappsphp20 abr 2009
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Contact Manager 3.0 - 'index.php?showGroup' Cross-Site Scripting
CVE-2009-4926webappsphp20 abr 2009
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
Creasito E-Commerce 1.3.16 - Authentication Bypass
CVE-2009-4925webappsphp20 abr 2009
Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16,
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Contact Manager 3.0 - 'edit.php?id' Cross-Site Scripting
CVE-2009-4926webappsphp20 abr 2009
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote a
23RIESGO
abrir
anteriorpágina 271 / 636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.