Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
24.451 exploits
Exploit-DBVexDay Proof
Sorinara Streaming Audio Player 0.9 - '.m3u' Local Stack Overflow
CVE-2009-2568localwindows05 may 2009
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Exploit-DBVexDay Proof
IceWarp Merak Mail Server 9.4.1 - 'Forgot Password' Input Validation
CVE-2009-1469webappsphp05 may 2009
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and Web
23RIESGO
abrir
Exploit-DBVexDay Proof
Winn ASP Guestbook 1.01b - Remote Database Disclosure
CVE-2009-4760webappsasp04 may 2009
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
Exploit-DBVexDay Proof
Openfire 3.x - jabber:iq:auth 'passwd_change' Remote Password Change
CVE-2009-1595remotemultiple04 may 2009
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authentic
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader 8.1.2 < 9.0 - 'getIcon()' Memory Corruption
CVE-2009-0927HIGHbajo ataquelocalwindows04 may 2009
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RIESGO
abrir
Exploit-DBVexDay Proof
Solaris 10 / OpenSolaris - 'dtrace' Local Kernel Denial of Service (PoC)
CVE-2009-1478dossolaris04 may 2009
Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, all
23RIESGO
abrir
Exploit-DBVexDay Proof
Bmxplay 0.4.4b - '.bmx' Local Buffer Overflow (PoC)
CVE-2009-4759doswindows04 may 2009
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) o
23RIESGO
abrir
Exploit-DBVexDay Proof
EW-MusicPlayer 0.8 - '.m3u' Local Buffer Overflow (PoC)
CVE-2009-4757doswindows04 may 2009
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (appl
23RIESGO
abrir
Exploit-DBVexDay Proof
GUPnP 0.12.7 - Message Handling Denial of Service
CVE-2009-2174doslinux03 may 2009
GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control m
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x (Sparc64) - '/proc/iomem' Local Denial of Service
CVE-2009-1914doslinux03 may 2009
The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc6
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercury Audio Player 1.21 - '.m3u' Local Stack Overflow
CVE-2009-4754localwindows01 may 2009
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Exploit-DBVexDay Proof
MiniTwitter 0.2b - Remote User Options Changer
CVE-2009-2574webappsphp01 may 2009
index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via
23RIESGO
abrir
Exploit-DBVexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Stack Overflow (3)
CVE-2009-4756localwindows01 may 2009
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Overwrite (SEH)
CVE-2009-4756localwindows01 may 2009
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
RM Downloader - '.smi' Universal Local Buffer Overflow
CVE-2009-4761localwindows01 may 2009
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Exploit-DBVexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Buffer Overflow (PoC)
CVE-2009-4756doswindows01 may 2009
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Stack Overflow (2)
CVE-2009-4756localwindows01 may 2009
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Addonics NAS Adapter FTP - Remote Denial of Service
CVE-2009-4753doshardware01 may 2009
Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
MiniTwitter 0.2b - Multiple SQL Injections
CVE-2009-2573webappsphp01 may 2009
Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenti
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercury Audio Player 1.21 - '.b4s' Local Stack Overflow
CVE-2009-4755localwindows30 abr 2009
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercury Audio Player 1.21 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-4754doswindows30 abr 2009
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Exploit-DBVexDay Proof
GnuTLS 2.6.x - libgnutls lib/gnutls_pk.c DSA Key Storage Remote Spoofing
CVE-2009-1416remotelinux30 abr 2009
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the i
23RIESGO
abrir
Exploit-DBVexDay Proof
GnuTLS 2.6.x - libgnutls lib/pk-libgcrypt.c Malformed DSA Key Handling Remote Denial of Service
CVE-2009-1415doslinux30 abr 2009
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.21 - 'css' Cross-Site Scripting
CVE-2009-1616webappsphp29 abr 2009
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Fax Viewer Control 10 - 'DCCFAXVW.dll' Remote Buffer Overflow
CVE-2009-2570remotewindows29 abr 2009
Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax
28RIESGO
abrir
Exploit-DBVexDay Proof
mpegable Player 2.12 - '.yuv' Local Stack Overflow (PoC)
CVE-2009-4758doswindows29 abr 2009
Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (applicat
23RIESGO
abrir
Exploit-DBVexDay Proof
MIM: InfiniX 1.2.003 - Multiple SQL Injections
CVE-2009-2451webappsphp28 abr 2009
Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec (Multiple Products) - Intel Common Base Agent Remote Command Execution
CVE-2009-1429remotewindows28 abr 2009
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Cente
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20/2.6.24/2.6.27_7-10 (Ubuntu 7.04/8.04/8.10 / Fedora Core 10 / OpenSuse 11.1) - SCTP FWD Memory Corruption Remote Overflow
CVE-2009-0065remotelinux28 abr 2009
Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linu
28RIESGO
abrir
Exploit-DBVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (2)
CVE-2009-1627localwindows27 abr 2009
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
anteriorpágina 449 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.