Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Universal Overwrite (SEH)
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - 'searchterm' Blind SQL Injection
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1614webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1615webappsphp
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading
23RIESGO
abrir
ReferênciaVexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
CVE-2009-1619webappsphp
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RIESGO
abrir
ReferênciaVexDay Proof
Opencart 1.1.8 - 'route' Local File Inclusion
CVE-2009-1621webappsphp
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir
ReferênciaVexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1624webappsphp
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi
23RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
CVE-2009-1627doswindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
CVE-2009-1627localwindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.asx' 'HREF' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.RAM' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.asx HREF' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
CVE-2007-4155remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
Soritong MP3 Player 1.0 - Local Buffer Overflow (SEH)
CVE-2009-1643localwindows
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow (PoC)
CVE-2009-1644doswindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir
ReferênciaVexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow
CVE-2009-1644localwindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.asx' Local Buffer Overflow
CVE-2009-1645localwindows
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
CVE-2009-1645localwindows
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
beLive 0.2.3 - 'arch.php?arch' Local File Inclusion
CVE-2009-1649webappsphp
Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir
ReferênciaVexDay Proof
2DayBiz Business Community Script - Multiple Vulnerabilities
CVE-2009-1652webappsphp
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
eLitius 1.0 - Remote Command Execution
CVE-2009-1659webappsphp
Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intende
23RIESGO
abrir
ReferênciaVexDay Proof
ViPlay3 < 3.00 - '.vpl' Local Stack Overflow (PoC)
CVE-2009-1660doswindows
Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (cr
23RIESGO
abrir
ReferênciaVexDay Proof
TCPDB 3.8 - Arbitrary Add Admin Account
CVE-2009-1670webappsphp
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin a
23RIESGO
abrir
ReferênciaVexDay Proof
Java SE Runtime Environment JRE 6 Update 13 - Multiple Vulnerabilities
CVE-2009-1671doswindows
Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Env
28RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP - 'PASV' Reply Client Remote Overflow (Metasploit)
CVE-2009-1675remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
43RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_gsticketsystem - 'catid' Blind SQL Injection
CVE-2009-1736webappsphp
SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Authentication Bypass
CVE-2009-1741webappsphp
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow re
23RIESGO
abrir
ReferênciaVexDay Proof
DGNews 3.0 Beta - 'id' SQL Injection
CVE-2009-1746webappsphp
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.