Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
24.451 exploits
Exploit-DBVexDay Proof
Mozilla Firefox 2.0.x - Nested 'window.print()' Denial of Service
CVE-2009-0821dosmultiple03 mar 2009
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested
23RIESGO
abrir
Exploit-DBVexDay Proof
Sopcast SopCore Control - 'sopocx.ocx' Command Execution
CVE-2009-0811remotewindows03 mar 2009
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
CVE-2009-4801webappsphp02 mar 2009
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir
Exploit-DBVexDay Proof
Media Commands - '.m3u' Local Overwrite (SEH)
CVE-2009-0885localwindows02 mar 2009
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'seccomp' System Call Security Bypass
CVE-2009-0835locallinux02 mar 2009
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell eDirectory iMonitor - 'Accept-Language' Request Buffer Overflow (PoC)
CVE-2009-0192doswindows02 mar 2009
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allow
28RIESGO
abrir
Exploit-DBVexDay Proof
NovaStor NovaNET 12 - 'DtbClsLogin()' Remote Stack Buffer Overflow
CVE-2009-0849remotewindows02 mar 2009
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute ar
28RIESGO
abrir
Exploit-DBVexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
CVE-2009-4805webappsphp02 mar 2009
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (SEH)
CVE-2009-0350localwindows02 mar 2009
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RIESGO
abrir
Exploit-DBVexDay Proof
Document Library 1.0.1 - Arbitrary Change Admin
CVE-2009-4806webappsasp02 mar 2009
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which
23RIESGO
abrir
Exploit-DBVexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
CVE-2009-4808webappsphp02 mar 2009
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir
Exploit-DBVexDay Proof
HTC Touch - vCard over IP Denial of Service
CVE-2008-6775doshardware02 mar 2009
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consum
23RIESGO
abrir
Exploit-DBVexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
CVE-2009-4807webappsphp02 mar 2009
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Blogsa 1.0 - 'Widgets.aspx' Cross-Site Scripting
CVE-2009-0814webappsasp02 mar 2009
Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
djbdns 1.05 - Long Response Packet Remote Cache Poisoning
CVE-2009-0858remotelinux27 feb 2009
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in
23RIESGO
abrir
Exploit-DBVexDay Proof
Irokez Blog 0.7.3.2 - Multiple Input Validation Vulnerabilities
CVE-2006-6771webappsphp27 feb 2009
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RIESGO
abrir
Exploit-DBVexDay Proof
Orbit Downloader 2.8.4 - 'Hostname' Remote Buffer Overflow
CVE-2009-0187remotewindows27 feb 2009
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere Application Server 6.1/7.0 - Administrative Console Cross-Site Scripting
CVE-2009-0855remotemultiple26 feb 2009
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSC 0.11.x - PKCS#11 Implementation Unauthorized Access
CVE-2009-0368locallinux26 feb 2009
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4426webappsphp25 feb 2009
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Cloned Process 'CLONE_PARENT' Local Origin Validation
CVE-2009-0028doslinux25 feb 2009
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent pr
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4425webappsphp25 feb 2009
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4528webappsphp25 feb 2009
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4427webappsphp25 feb 2009
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir
Exploit-DBVexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
CVE-2008-4428webappsphp25 feb 2009
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier
23RIESGO
abrir
Exploit-DBVexDay Proof
Wesnoth 1.x - PythonAI Remote Code Execution
CVE-2009-0367remotelinux25 feb 2009
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute ar
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 4 - 'feeds:' URI Null Pointer Dereference Remote Denial of Service
CVE-2009-0744dososx25 feb 2009
Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and appl
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
CVE-2009-0520remoteunix24 feb 2009
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RIESGO
abrir
Exploit-DBVexDay Proof
Magento 1.2 - '/app/code/core/Mage/Adminhtml/controllers/IndexController.php?email' Cross-Site Scripting
CVE-2009-0541webappsphp24 feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Magento 1.2 - 'downloader/index.php' Cross-Site Scripting
CVE-2009-0541webappsphp24 feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir
anteriorpágina 455 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.