Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - FTP URI Arbitrary FTP Server Command Execution
CVE-2004-1166—remotewindows06 dic 2004
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KDE FTP - KIOSlave URI Arbitrary FTP Server Command Execution
CVE-2004-1165—remotelinux06 dic 2004
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hosting Controller 0.6.1 Hotfix 1.4 - Directory Browsing
CVE-2004-1217—remotewindows05 dic 2004
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PAFileDB 3.1 - Error Message Full Path Disclosure
CVE-2005-0780—webappsphp04 dic 2004
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Advanced Guestbook 2.2/2.3 - Cross-Site Scripting
CVE-2004-1213—webappsphp02 dic 2004
Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kreed 1.05 - Format String / Denial of Service
CVE-2004-1214—doswindows02 dic 2004
Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format speci
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kreed 1.05 - Format String / Denial of Service
CVE-2004-1216—doswindows02 dic 2004
The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server fr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blog Torrent 0.8 - Directory Traversal
CVE-2004-1212—webappsphp02 dic 2004
Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kreed 1.05 - Format String / Denial of Service
CVE-2004-1215—doswindows02 dic 2004
Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RSSH 2.x - Arbitrary Command Execution
CVE-2004-1161—remotelinux02 dic 2004
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (2)
CVE-2004-2513—remotewindows01 dic 2004
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aspell (word-list-compress) - Command Line Stack Overflow
CVE-2004-0548—locallinux01 dic 2004
Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (2)
CVE-2004-1211—remotewindows01 dic 2004
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01a - 'check' Buffer Overflow
CVE-2004-1211—doswindows01 dic 2004
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01a - 'check' Buffer Overflow
CVE-2004-2513—doswindows01 dic 2004
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IPCop 1.4.1 - Web Administration Interface Proxy Log HTML Injection
CVE-2004-1210—webappsmultiple30 nov 2004
Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (1)
CVE-2004-1211—remotewindows30 nov 2004
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (1)
CVE-2004-2513—remotewindows30 nov 2004
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Orbz Game 2.10 - Remote Buffer Overflow (PoC)
CVE-2004-1208—doswindows29 nov 2004
Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and po
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 5.03 - 'RNFR' Buffer Overflow
CVE-2001-1021—doswindows29 nov 2004
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDT
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 5.03 - MKD Remote Buffer Overflow
CVE-2004-1135—doswindows29 nov 2004
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (3)
CVE-2004-1211—remotewindows29 nov 2004
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
File ELF 4.x - Header Buffer Overflow
CVE-2004-1304—remotelinux29 nov 2004
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary cod
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 4.3.7/5.0.0RC3 - 'memory_limit' Remote Overflow
CVE-2004-0594—remotelinux27 nov 2004
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when reg
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
pntresmailer 6.0 - Directory Traversal
CVE-2004-1206—webappsphp26 nov 2004
Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MailEnable Mail Server IMAP 1.52 - Remote Buffer Overflow
CVE-2004-2501—remotewindows25 nov 2004
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote at
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alex Heiphetz Group eZshopper - 'loadpage.cgi' Directory Traversal
CVE-2000-0187—webappscgi25 nov 2004
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.x/2.6.x - Local Denial of Service / Memory Disclosure
CVE-2004-1074—doslinux25 nov 2004
The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
InShop and InMail - Cross-Site Scripting
CVE-2004-1196—webappscgi25 nov 2004
Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Winamp 5.06 - 'IN_CDDA.dll' Remote Buffer Overflow
CVE-2004-1119—remotewindows24 nov 2004
Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote att
28RIESGO
abrir ↗
← anteriorpágina 508 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.