Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
PY Software Active Webcam 4.3/5.5 - WebServer Multiple Vulnerabilities
CVE-2005-0731—remotewindows10 mar 2005
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumpti
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
All Enthusiast PhotoPost PHP Pro 5.0 - 'adm-photo.php' Arbitrary Image Manipulation
CVE-2005-0776—webappsphp10 mar 2005
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, wh
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Download Center Lite (DCL) 1.5 - Remote File Inclusion
CVE-2005-0680—webappsphp10 mar 2005
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation (1)
CVE-2005-0736—locallinux09 mar 2005
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Newsscript - Access Validation
CVE-2005-0735—webappscgi08 mar 2005
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
paNews 2.0b4 - Remote Admin Creation SQL Injection
CVE-2005-0647—webappsphp08 mar 2005
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.x/6.0 - Offline Mode Status Remote Buffer Overflow
CVE-2005-0737—remotewindows08 mar 2005
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YaBB 2.0 - Remote UsersRecentPosts Cross-Site Scripting
CVE-2005-0741—webappsphp08 mar 2005
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpWebLog 0.5.3 - Arbitrary File Inclusion
CVE-2005-0698—webappsphp07 mar 2005
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
CVE-2005-0688—doswindows07 mar 2005
Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
CVE-2005-1649—doswindows07 mar 2005
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attac
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP mcNews 1.3 - 'skinfile' Remote File Inclusion
CVE-2005-0720—webappsphp07 mar 2005
PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Database 8i/9i - Multiple Directory Traversal Vulnerabilities
CVE-2005-0701—remotewindows07 mar 2005
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrar
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (1)
CVE-2005-0689—webappscgi07 mar 2005
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - 'myadmin.php' Database Dumper
CVE-2005-0700—webappsphp07 mar 2005
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 10 - '.smil' Local Buffer Overflow
CVE-2005-0455—localwindows07 mar 2005
Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlaye
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
CVE-2005-0581—remotewindows06 mar 2005
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
CVE-2005-0582—remotewindows06 mar 2005
Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code vi
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PlatinumFTPServer 1.0.18 - Multiple Malformed User Name Connection Denial of Service Vulnerabilities
CVE-2005-0779—doswindows05 mar 2005
PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Form Mail 2.3 - Arbitrary File Inclusion
CVE-2005-0678—webappsphp05 mar 2005
PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 2.0.52 - GET Denial of Service
CVE-2004-0942—dosmultiple04 mar 2005
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP G
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ca3de - Multiple Vulnerabilities
CVE-2005-0671—remotemultiple03 mar 2005
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trillian Basic 3.0 - '.png' Image Processing Buffer Overflow
CVE-2005-0633—doswindows02 mar 2005
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ProjectBB 0.4.5.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0650—webappsphp02 mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foxmail 1.1.0.1 - POP3 Temp Dir Stack Overflow
CVE-2005-0635—remotewindows02 mar 2005
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AWStats 5.7 < 6.2 - Multiple Remote s
CVE-2005-0438—webappscgi02 mar 2005
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
427BB 2.x - Multiple Remote HTML Injection Vulnerabilities
CVE-2005-0629—webappsphp01 mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'mod.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0670—webappsphp01 mar 2005
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPNews 1.2.3/1.2.4 - 'auth.php' Remote File Inclusion
CVE-2005-0632—webappsphp01 mar 2005
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to exec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0670—webappsphp01 mar 2005
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
← anteriorpágina 500 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.