Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4426webappsphp25 feb 2009
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 4 - 'feeds:' URI Null Pointer Dereference Remote Denial of Service
CVE-2009-0744dososx25 feb 2009
Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and appl
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Cloned Process 'CLONE_PARENT' Local Origin Validation
CVE-2009-0028doslinux25 feb 2009
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent pr
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4425webappsphp25 feb 2009
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4528webappsphp25 feb 2009
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4428webappsphp25 feb 2009
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier
23RIESGO
abrir
Exploit-DBVexDay Proof
Wesnoth 1.x - PythonAI Remote Code Execution
CVE-2009-0367remotelinux25 feb 2009
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute ar
28RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4427webappsphp25 feb 2009
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir
Exploit-DBVexDay Proof
Magento 1.2 - 'downloader/index.php' Cross-Site Scripting
CVE-2009-0541webappsphp24 feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
CVE-2009-0520remoteunix24 feb 2009
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RIESGO
abrir
Exploit-DBVexDay Proof
Magento 1.2 - '/app/code/core/Mage/Admin/Model/Session.php?login['Username']' Cross-Site Scripting
CVE-2009-0541webappsphp24 feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Magento 1.2 - '/app/code/core/Mage/Adminhtml/controllers/IndexController.php?email' Cross-Site Scripting
CVE-2009-0541webappsphp24 feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! / Mambo Component gigCalendar 1.0 - 'banddetails.php' SQL Injection
CVE-2009-0730webappsphp23 feb 2009
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_q
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'sock.c' SO_BSDCOMPAT Option Information Disclosure
CVE-2009-0676locallinux20 feb 2009
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct
23RIESGO
abrir
Exploit-DBVexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
CVE-2009-0659doswindows16 feb 2009
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'make_indexed_dir()' Local Denial of Service
CVE-2009-0746doslinux16 feb 2009
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7
23RIESGO
abrir
Exploit-DBVexDay Proof
Enomaly ECP / Enomalism < 2.2.1 - Multiple Local Vulnerabilities
CVE-2009-0390localmultiple16 feb 2009
Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows lo
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 6.0.9 - XPath Expression Remote Denial of Service
CVE-2009-0819doslinux14 feb 2009
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial
28RIESGO
abrir
Exploit-DBVexDay Proof
Vlinks 1.1.6 - 'id' SQL Injection
CVE-2009-5091webappsphp13 feb 2009
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
CVE-2009-5088webappsphp13 feb 2009
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
CmsFaethon 2.2.0 - 'item' SQL Injection
CVE-2009-5094webappsphp13 feb 2009
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
ea-gBook 0.1 - Remote Command Execution / Remote File Inclusion
CVE-2009-5095webappsphp13 feb 2009
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
CVE-2009-5089webappsphp13 feb 2009
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RIESGO
abrir
Exploit-DBVexDay Proof
Poppler 0.10.3 - Denial of Service
CVE-2009-0755doslinux12 feb 2009
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir
Exploit-DBVexDay Proof
Poppler 0.10.3 - Denial of Service
CVE-2009-0756doslinux12 feb 2009
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir
Exploit-DBVexDay Proof
GeoVision Digital Video Surveillance System 8.2 - Arbitrary File Disclosure
CVE-2009-5087remotewindows11 feb 2009
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Bloggeruniverse 2.0 Beta - 'id' SQL Injection
CVE-2009-5090webappsphp11 feb 2009
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir
anteriorpágina 277 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.