Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0275webappsphp14 ene 2009
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to
23RIESGO
abrir
Exploit-DBVexDay Proof
Dark Age CMS 2.0 - 'login.php' SQL Injection
CVE-2009-0326webappsphp14 ene 2009
SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Dark Age CMS 0.2c Beta - Authentication Bypass
CVE-2009-0326webappsphp13 ene 2009
SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
CVE-2009-0266doswindows12 ene 2009
Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
CVE-2006-0564localwindows12 ene 2009
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RIESGO
abrir
Exploit-DBVexDay Proof
Openfire 3.6.2 - 'user-properties.jsp' Cross-Site Scripting
CVE-2009-0496webappsjsp08 ene 2009
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere DataPower XML Security Gateway 3.6.1 XS40 - Remote Denial of Service
CVE-2009-0120dosmultiple08 ene 2009
The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of
23RIESGO
abrir
Exploit-DBVexDay Proof
Openfire 3.6.2 - 'log.jsp' Directory Traversal
CVE-2009-0497webappsjsp08 ene 2009
Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Openfire 3.6.2 - 'group-summary.jsp' Cross-Site Scripting
CVE-2009-0496webappsjsp08 ene 2009
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Openfire 3.6.2 - 'log.jsp' Cross-Site Scripting
CVE-2009-0496webappsjsp08 ene 2009
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0829webappsphp07 ene 2009
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple CA Service Management Products - Remote Command Execution
CVE-2009-0043remotewindows07 ene 2009
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not pro
35RIESGO
abrir
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/auftrag_job.jsp?Pfad' Direct Request Information Disclosure
CVE-2009-0700webappsjsp07 ene 2009
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RIESGO
abrir
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information Disclosure
CVE-2009-0700webappsjsp07 ene 2009
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RIESGO
abrir
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - '/pagesUTF8/auftrag_allgemeinauftrag.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-0699webappsjsp07 ene 2009
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.MERGEWORKSPACE SQL Injection
CVE-2008-3983localmultiple06 ene 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir
Exploit-DBVexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0121webappsphp06 ene 2009
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.REMOVEWORKSPACE SQL Injection
CVE-2008-3984localmultiple06 ene 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
CVE-2009-3429localwindows04 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows03 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
CVE-2009-3429localwindows03 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.2.8 gd library - 'imageRotate()' Information Leak
CVE-2008-5498localmultiple02 ene 2009
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the co
23RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows02 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0709webappsphp01 ene 2009
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0710webappsphp01 ene 2009
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (2)
CVE-2008-5821dososx01 ene 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RIESGO
abrir
Exploit-DBVexDay Proof
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
CVE-2008-6748remotewindows01 ene 2009
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6758webappsphp01 ene 2009
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6765webappsphp01 ene 2009
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a mo
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (1)
CVE-2008-5821dososx01 ene 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RIESGO
abrir
anteriorpágina 280 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.