Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
LinPopUp 1.2 - Remote Buffer Overflow
CVE-2004-1282remotelinux15 dic 2004
Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Exploit-DBVexDay Proof
Michael Kohn Ringtone Tools 2.22 - '.EMelody' File Remote Buffer Overflow
CVE-2004-1292remotelinux15 dic 2004
Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execu
28RIESGO
abrir
Exploit-DBVexDay Proof
ABC2MIDI 2004-12-04 - Multiple Stack Buffer Overflow Vulnerabilities
CVE-2004-1256remotemultiple15 dic 2004
Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote att
28RIESGO
abrir
Exploit-DBVexDay Proof
PCAL 4.x - Calendar File 'getline' Remote Buffer Overflow
CVE-2004-1289remotelinux15 dic 2004
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for p
28RIESGO
abrir
Exploit-DBVexDay Proof
phpGroupWare 0.9.x - 'viewticket_details.php?ticket_id' Cross-Site Scripting
CVE-2004-1384webappsphp15 dic 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
ABCPP 1.3 - Directive Handler Buffer Overflow
CVE-2004-1259remotewindows15 dic 2004
Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.22-28/2.6.9 - 'igmp.c' Local Denial of Service
CVE-2004-1137doslinux14 dic 2004
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local an
28RIESGO
abrir
Exploit-DBVexDay Proof
Active Server Corner ASP Calendar 1.0 - Administrative Access
CVE-2004-1400webappsasp14 dic 2004
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unaut
23RIESGO
abrir
Exploit-DBVexDay Proof
ASP-Rider - SQL Injection
CVE-2004-1401webappsasp14 dic 2004
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and b
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.28/2.6.9 - 'scm_send Local' Denial of Service
CVE-2004-1016doslinux14 dic 2004
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'showflat.php?Cat' Cross-Site Scripting
CVE-2004-2510webappsphp13 dic 2004
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'login.php?Cat' Cross-Site Scripting
CVE-2004-2509webappsphp13 dic 2004
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera Web Browser 7.54 - 'KDE KFMCLIENT' Remote Command Execution
CVE-2004-1491doslinux13 dic 2004
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitr
28RIESGO
abrir
Exploit-DBVexDay Proof
Lithtech Engine (new protocol) - Socket Unreacheable Denial of Service
CVE-2004-1395doswindows13 dic 2004
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'online.php?Cat' Cross-Site Scripting
CVE-2004-2509webappsphp13 dic 2004
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'calendar.php?Cat' Cross-Site Scripting
CVE-2004-2509webappsphp13 dic 2004
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple Vendor - TCP Session Acknowledgement Number Denial of Service
CVE-2005-1184dosmultiple13 dic 2004
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) vi
35RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 2.x - External Transformations Remote Command Execution
CVE-2004-1147webappsphp13 dic 2004
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to
28RIESGO
abrir
Exploit-DBVexDay Proof
Citadel/UX 6.27 - Format String
CVE-2004-1192remotelinux12 dic 2004
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute ar
28RIESGO
abrir
Exploit-DBVexDay Proof
Debian top - Format String
CVE-2000-0998locallinux12 dic 2004
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" fun
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy Software Products LPPassWd 1.1.22 - Resource Limit Denial of Service
CVE-2004-1269doswindows11 dic 2004
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Wget 1.x - Multiple Vulnerabilities
CVE-2004-1488remotelinux10 dic 2004
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which m
28RIESGO
abrir
Exploit-DBVexDay Proof
NapShare 1.2 - Remote Buffer Overflow (2)
CVE-2004-1286remotelinux10 dic 2004
Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows re
28RIESGO
abrir
Exploit-DBVexDay Proof
F-Secure Policy Manager 5.11 - 'FSMSH.dll' CGI Application Installation Full Path Disclosure
CVE-2004-1223remotewindows09 dic 2004
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Adobe Version Cue - Local Privilege Escalation
CVE-2005-1307localosx08 dic 2004
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory
23RIESGO
abrir
Exploit-DBVexDay Proof
darryl burgdorf weblibs 1.0 - Directory Traversal
CVE-2004-1221webappsphp07 dic 2004
Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. se
23RIESGO
abrir
Exploit-DBVexDay Proof
MD5 - Message Digest Algorithm Hash Collision
CVE-2004-2761CRITICALdosmultiple07 dic 2004
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to co
48RIESGO
abrir
Exploit-DBVexDay Proof
Battlefield 1942 1.6.19 + Vietnam 1.2 - Broadcast Client Crash
CVE-2004-1220doswindows07 dic 2004
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
KDE FTP - KIOSlave URI Arbitrary FTP Server Command Execution
CVE-2004-1165remotelinux06 dic 2004
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - FTP URI Arbitrary FTP Server Command Execution
CVE-2004-1166remotewindows06 dic 2004
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute
35RIESGO
abrir
anteriorpágina 507 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.