Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
iWare CMS 5.0.4 - Multiple SQL Injections
CVE-2006-6446webappsphp29 mar 2009
SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
pam-krb5 < 3.13 - Local Privilege Escalation
CVE-2009-0360locallinux29 mar 2009
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries
23RIESGO
abrir
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.7.0 - 'NLST' Denial of Service
CVE-2008-5626doswindows27 mar 2009
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir
Exploit-DBVexDay Proof
freeSSHd 1.2.1 - 'rename' Remote Buffer Overflow (SEH)
CVE-2008-6899remotewindows27 mar 2009
Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft GdiPlus - EMF GpFont.SetData Integer Overflow (PoC)
CVE-2009-1217doswindows24 mar 2009
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Jinzora Media Jukebox 2.8 - 'name' Local File Inclusion
CVE-2009-2313webappsphp24 mar 2009
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu
23RIESGO
abrir
Exploit-DBVexDay Proof
Femitter FTP Server 1.x - (Authenticated) Multiple Vulnerabilities
CVE-2008-2032remotewindows24 mar 2009
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending
23RIESGO
abrir
Exploit-DBVexDay Proof
Codice CMS 2 - Command Execution (via SQL Injection)
CVE-2009-2309webappsphp23 mar 2009
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Exploit-DBVexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Universal Overwrite (SEH)
CVE-2004-0964localwindows23 mar 2009
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RIESGO
abrir
Exploit-DBVexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
CVE-2009-4790remotewindows23 mar 2009
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modif
23RIESGO
abrir
Exploit-DBVexDay Proof
WBB3 rGallery 1.2.3 - 'UserGallery' Blind SQL Injection
CVE-2009-2311webappsphp23 mar 2009
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
X-BLC 0.2.0 - 'get_read.php?section' SQL Injection
CVE-2009-2310webappsphp23 mar 2009
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
CVE-2009-4800remotewindows23 mar 2009
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
ExpressionEngine 1.6 - Avtaar Name HTML Injection
CVE-2009-1070webappsphp22 mar 2009
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earli
23RIESGO
abrir
Exploit-DBVexDay Proof
Racer 0.5.3 Beta 5 - Remote Stack Buffer Overflow
CVE-2007-4370remotewindows20 mar 2009
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RIESGO
abrir
Exploit-DBVexDay Proof
Xlight FTP Server 3.2 - 'user' SQL Injection
CVE-2009-4795remotemultiple19 mar 2009
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow rem
23RIESGO
abrir
Exploit-DBVexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
CVE-2010-4151webappsphp18 mar 2009
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Foxit Reader 3.0 (Build 1301) - PDF Universal Buffer Overflow
CVE-2009-0837localwindows13 mar 2009
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RIESGO
abrir
Exploit-DBVexDay Proof
YAP 1.1.1 - 'index.php' Local File Inclusion
CVE-2009-1038webappsphp13 mar 2009
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-list_file_gallery.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-listpages.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-galleries.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
SlySoft (Multiple Products) - Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
CVE-2009-0824localwindows12 mar 2009
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.
23RIESGO
abrir
Exploit-DBVexDay Proof
phpmysport 1.4 - Cross-Site Scripting / SQL Injection
CVE-2010-1109webappsphp12 mar 2009
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
PostgreSQL 8.3.6 - Conversion Encoding Remote Denial of Service
CVE-2009-0922doslinux11 mar 2009
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of servi
28RIESGO
abrir
Exploit-DBVexDay Proof
IBM System Director Agent 5.20 - CIM Server Privilege Escalation
CVE-2009-0880localwindows10 mar 2009
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir
Exploit-DBVexDay Proof
CMS WEBjump! - Multiple SQL Injections
CVE-2009-4892webappsphp10 mar 2009
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun xVM VirtualBox 2.0/2.1 - Local Privilege Escalation
CVE-2009-0876locallinux10 mar 2009
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain p
23RIESGO
abrir
Exploit-DBVexDay Proof
NextApp Echo < 2.1.1 - XML Injection
CVE-2009-5135remotemultiple10 mar 2009
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RIESGO
abrir
Exploit-DBVexDay Proof
EO Video 1.36 - Playlist Overwrite (SEH)
CVE-2008-3733localwindows09 mar 2009
Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir
anteriorpágina 275 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.