Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Adobe 8.1.4/9.1 - 'customDictionaryOpen()' Code Execution
CVE-2009-1493remotelinux
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Cmimarketplace - 'viewit' Directory Traversal
CVE-2009-1496webappsphp
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote at
38RIESGO
abrir
ReferênciaVexDay Proof
ProjectCMS 1.0b - 'index.php?sn' SQL Injection
CVE-2009-1500webappsphp
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
eLitius 1.0 - 'banner-details.php?id' SQL Injection
CVE-2009-1506webappsphp
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
S-CMS 1.1 Stable - 'page' Local File Inclusion
CVE-2009-1502webappsphp
Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
X-Forum 0.6.2 - Remote Command Execution
CVE-2009-1508webappsphp
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
CVE-2009-1511doswindows
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RIESGO
abrir
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0233webappsphp
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
CVE-2008-0234doswindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RIESGO
abrir
ReferênciaVexDay Proof
pecio CMS 1.1.5 - 'index.php?language' Local File Inclusion
CVE-2009-1519webappsphp
Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'mshtml.dll' Null Pointer Dereference
CVE-2007-0811doswindows
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denia
28RIESGO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Download Manager 0.2 - Arbitrary File Upload
CVE-2008-3362webappsphp
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress a
28RIESGO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0595webappsphp
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled
28RIESGO
abrir
ReferênciaVexDay Proof
Qt QuickTeam - Multiple Remote File Inclusions
CVE-2009-1551webappsphp
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP cod
28RIESGO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Universal Overwrite (SEH)
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow
CVE-2009-1592remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Post 1.0 - Cookie Modification Privilege Escalation
CVE-2006-3772webappsphp
PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu
28RIESGO
abrir
ReferênciaVexDay Proof
TaskFreak! 0.6.1 - SQL Injection
CVE-2008-0270webappsphp
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - 'searchterm' Blind SQL Injection
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1614webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1615webappsphp
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading
23RIESGO
abrir
ReferênciaVexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
CVE-2009-1619webappsphp
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RIESGO
abrir
ReferênciaVexDay Proof
Total Video Player 1.03 - '.m3u' File Local Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
CVE-2009-1627doswindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
CVE-2009-1627localwindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
CVE-2009-1638webappsasp
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.asx' 'HREF' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.