Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
24.451 exploits
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - '/pagesUTF8/auftrag_allgemeinauftrag.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-0699webappsjsp07 ene 2009
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear
23RIESGO
abrir
Exploit-DBVexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0829webappsphp07 ene 2009
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information Disclosure
CVE-2009-0700webappsjsp07 ene 2009
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RIESGO
abrir
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/auftrag_job.jsp?Pfad' Direct Request Information Disclosure
CVE-2009-0700webappsjsp07 ene 2009
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.REMOVEWORKSPACE SQL Injection
CVE-2008-3984localmultiple06 ene 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.MERGEWORKSPACE SQL Injection
CVE-2008-3983localmultiple06 ene 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir
Exploit-DBVexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0121webappsphp06 ene 2009
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
CVE-2009-3429localwindows04 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows03 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
CVE-2009-3429localwindows03 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.2.8 gd library - 'imageRotate()' Information Leak
CVE-2008-5498localmultiple02 ene 2009
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the co
23RIESGO
abrir
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows02 ene 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0710webappsphp01 ene 2009
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6765webappsphp01 ene 2009
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a mo
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (1)
CVE-2008-5821dososx01 ene 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (2)
CVE-2008-5821dososx01 ene 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RIESGO
abrir
Exploit-DBVexDay Proof
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
CVE-2008-6748remotewindows01 ene 2009
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6758webappsphp01 ene 2009
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0709webappsphp01 ene 2009
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
Audio File Library 0.2.6 - libaudiofile 'msadpcm.c .WAV' File Processing Buffer Overflow
CVE-2008-5824remotelinux30 dic 2008
Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a
23RIESGO
abrir
Exploit-DBVexDay Proof
ViArt Shop 3.5 - 'manuals_search.php?manuals_search' Cross-Site Scripting
CVE-2008-6757webappsphp29 dic 2008
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
xterm - DECRQSS Remote Command Execution
CVE-2006-7236remotelinux29 dic 2008
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 9/10/11 - '.WAV' File Parsing Code Execution
CVE-2008-5745remotewindows29 dic 2008
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RIESGO
abrir
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-1647remotewindows28 dic 2008
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir
Exploit-DBVexDay Proof
Miniweb 2.0 - Authentication Bypass
CVE-2008-2197webappsphp28 dic 2008
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-4584remotewindows28 dic 2008
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5875webappsphp24 dic 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5864webappsphp24 dic 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5865webappsphp24 dic 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5875webappsphp23 dic 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RIESGO
abrir
anteriorpágina 459 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.