Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'cat.asp' Multiple SQL Injections
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Logwatch 2.6 Secure Script - Denial of Service
CVE-2005-1061doslinux20 abr 2005
The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via ce
23RIESGO
abrir
Exploit-DBVexDay Proof
Neslo Desktop Rover 3.0 - Malformed Packet Remote Denial of Service
CVE-2005-1204dosmultiple20 abr 2005
Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application cras
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple OS (Win32/Aix/Cisco) - Crafted ICMP Messages Denial of Service (MS05-019)
CVE-2004-0790dosmultiple20 abr 2005
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via
45RIESGO
abrir
Exploit-DBVexDay Proof
ECommPro 3.0 - 'Admin/login.asp' SQL Injection
CVE-2005-1412webappsasp20 abr 2005
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Ocean12 Calendar Manager 1.0 - Admin Form SQL Injection
CVE-2005-1223webappsphp20 abr 2005
Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Netref 4.2 - 'Cat_for_gen.php' Remote PHP Script Injection
CVE-2005-1222webappsphp20 abr 2005
cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct pa
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Labs - '.proFile' File URI Cross-Site Scripting
CVE-2005-1233webappsphp20 abr 2005
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal 3.1.2 - 'inc_rating.asp' Multiple SQL Injections
CVE-2005-1236webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PMSoftware Simple Web Server 1.0 - Remote Stack Overflow
CVE-2005-1173remotewindows20 abr 2005
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET req
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'detail.asp' Multiple SQL Injections
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Labs - '.proFile' Dir URI Cross-Site Scripting
CVE-2005-1233webappsphp20 abr 2005
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal 3.1.2 - 'type.asp?iCat' SQL Injection
CVE-2005-1236webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'default.asp' Multiple SQL Injections
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal 3.1.2 - 'inc_poll_voting.asp?DAT_PARENT' SQL Injection
CVE-2005-1236webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'inc_vote.asp' Multiple SQL Injections
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'search.asp?iChannel' SQL Injection
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
DUportal Pro 3.4 - 'result.asp' Multiple SQL Injections
CVE-2005-1224webappsasp20 abr 2005
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
CityPost PHP LNKX 52.0 - 'message.php' Cross-Site Scripting
CVE-2005-4670webappsphp19 abr 2005
Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
CityPost Simple PHP Upload - 'Simple-upload-53.php' Cross-Site Scripting
CVE-2005-4671webappsphp19 abr 2005
Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Exchange Server - Remote Code Execution (MS05-021)
CVE-2005-0560remotewindows19 abr 2005
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 98/2000 Explorer - Preview Pane Script Injection
CVE-2005-1191remotewindows19 abr 2005
The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostroph
28RIESGO
abrir
Exploit-DBVexDay Proof
eGroupWare 1.0 - '/tts/index.php?filter' SQL Injection
CVE-2005-1203webappsphp18 abr 2005
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
eGroupWare 1.0 - 'index.php?cats_app' SQL Injection
CVE-2005-1203webappsphp18 abr 2005
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
eGroupWare 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-1202webappsphp18 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
MVNForum 1.0 - Search Cross-Site Scripting
CVE-2005-1183webappsphp18 abr 2005
Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or H
23RIESGO
abrir
Exploit-DBVexDay Proof
eGroupWare 1.0 - '/sitemgr-site/index.php?category_id' Cross-Site Scripting
CVE-2005-1202webappsphp18 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
CVE-2005-0048doswindows17 abr 2005
Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
CVE-2004-0230doswindows17 abr 2005
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial o
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Malformed IP Options Denial of Service (MS05-019)
CVE-2004-1060doswindows17 abr 2005
Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause
45RIESGO
abrir
anteriorpágina 492 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.