Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
CVE-2009-197818 ago 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
50RIESGO
abrir
Metasploit500
Linux Kernel Sendpage Local Privilege Escalation
CVE-2009-269213 ago 2009
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RIESGO
abrir
Metasploit300
Microsoft OWC Spreadsheet HTMLURL Buffer Overflow
CVE-2009-153411 ago 2009
Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,
50RIESGO
abrir
Metasploit400
BlazeDVD 6.1 PLF Buffer Overflow
CVE-2006-619903 ago 2009
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir
Metasploit500
SAP Business One License Manager 2005 Buffer Overflow
CVE-2009-498801 ago 2009
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RIESGO
abrir
Metasploit500
Millenium MP3 Studio 2.0 (PLS File) Stack Buffer Overflow
CVE-2009-20002HIGH30 jul 2009
Millenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit600
Joomla 1.5.12 TinyBrowser File Upload Code Execution
CVE-2011-490822 jul 2009
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RIESGO
abrir
Metasploit600
DD-WRT HTTP Daemon Arbitrary Command Execution
CVE-2009-276520 jul 2009
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers
60RIESGO
abrir
Metasploit300
Microsoft OWC Spreadsheet msDataSourceObject Memory Corruption
CVE-2009-113613 jul 2009
The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 an
50RIESGO
abrir
Metasploit300
Firefox 3.5 escape() Return Value Memory Corruption
CVE-2009-247713 jul 2009
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RIESGO
abrir
Metasploit200
AwingSoft Winds3D Player SceneURL Buffer Overflow
CVE-2009-458810 jul 2009
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie
50RIESGO
abrir
Metasploit600
Wyse Rapport Hagent Fake Hserver Command Execution
CVE-2009-069510 jul 2009
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RIESGO
abrir
Metasploit300
Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption
CVE-2008-0015HIGHbajo ataque05 jul 2009
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in
100RIESGO
abrir
Metasploit600
ColdFusion 8.0.1 Arbitrary File Upload and Execute
CVE-2009-226503 jul 2009
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
Metasploit300
Media Jukebox 8.0.400 Buffer Overflow (SEH)
CVE-2009-265001 jul 2009
Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a d
50RIESGO
abrir
Metasploit400
HT-MP3Player 1.0 HT3 File Parsing Buffer Overflow
CVE-2009-248529 jun 2009
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RIESGO
abrir
Metasploit500
Timbuktu PlughNTCommand Named Pipe Buffer Overflow
CVE-2009-139425 jun 2009
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code
50RIESGO
abrir
Metasploit500
VideoLAN Client (VLC) Win32 smb:// URI Buffer Overflow
CVE-2009-248424 jun 2009
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.
50RIESGO
abrir
Metasploit600
Nagios3 statuswml.cgi Ping Command Execution
CVE-2009-228822 jun 2009
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RIESGO
abrir
Metasploit400
Bopup Communications Server Buffer Overflow
CVE-2009-222718 jun 2009
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2012-508117 jun 2009
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
30RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-13098HIGH17 jun 2009
BouncyCastle JCE TLS Bleichenbacher/ROBOT
41RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-616817 jun 2009
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (f
23RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-13099HIGH17 jun 2009
wolfSSL Bleichenbacher/ROBOT
41RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-100038517 jun 2009
The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding. Thi
23RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1237317 jun 2009
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550
23RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1738217 jun 2009
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build
23RIESGO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2016-688317 jun 2009
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a B
23RIESGO
abrir
Metasploit300
Slowloris Denial of Service Attack
CVE-2010-222717 jun 2009
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-En
30RIESGO
abrir
Metasploit300
Slowloris Denial of Service Attack
CVE-2007-675017 jun 2009
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP
40RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.