Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.251exploits catalogados
37.816CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
TABS MailCarrier 2.51 - Remote Buffer Overflow
CVE-2004-1638—remotewindows16 nov 2004
Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MiniShare 1.4.1 - Remote Buffer Overflow (2)
CVE-2004-2271—remotewindows16 nov 2004
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vBulletin - 'LAST.php' SQL Injection
CVE-2004-1515—webappsphp15 nov 2004
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0936—localmultiple14 nov 2004
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global he
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0932—localmultiple14 nov 2004
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0937—localmultiple14 nov 2004
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0934—localmultiple14 nov 2004
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and gl
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0933—localmultiple14 nov 2004
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-0935—localmultiple14 nov 2004
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compress
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-1096—localmultiple14 nov 2004
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to by
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple AntiVirus - '.zip' Detection Bypass
CVE-2004-2442—localmultiple14 nov 2004
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows S
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 4.1.1 - Multiple IP Options Denial of Service Vulnerabilities
CVE-2004-1109—doswindows12 nov 2004
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - Multiple Input Validation Vulnerabilities
CVE-2004-2725—webappsphp12 nov 2004
Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IPSwitch IMail 8.13 - 'DELETE' Remote Stack Overflow
CVE-2004-1520—remotewindows12 nov 2004
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SlimFTPd 3.15 - Remote Buffer Overflow
CVE-2004-2418—remotewindows10 nov 2004
Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.27/2.6.8 - 'binfmt_elf' Executable File Read
CVE-2004-1073—locallinux10 nov 2004
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XFree86 4.3 - Font Information File Buffer Overflow
CVE-2004-0083—locallinux10 nov 2004
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qwik SMTP 0.3 - Format String
CVE-2004-2677—remotelinux09 nov 2004
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CCProxy Log - Remote Stack Overflow
CVE-2004-2416—remotewindows09 nov 2004
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GE
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ability Server 2.34 (Unix) - FTP 'STOR' Remote Buffer Overflow
CVE-2004-1626—remotewindows07 nov 2004
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code v
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MiniShare 1.4.1 - Remote Buffer Overflow (1)
CVE-2004-2271—remotewindows07 nov 2004
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Monolith Lithtech Game Engine - Multiple Remote Format String Vulnerabilities
CVE-2004-1500—remotemultiple05 nov 2004
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to caus
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trend Micro ScanMail for Domino 2.51/2.6 - Remote File Disclosure
CVE-2004-1003—remotemultiple05 nov 2004
Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TIPS MailPost 5.1.1 - Remote File Enumeration
CVE-2004-1102—webappscgi03 nov 2004
MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested f
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TIPS MailPost 5.1.1 - Error Message Cross-Site Scripting
CVE-2004-1101—webappscgi03 nov 2004
mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TIPS MailPost 5.1.1 - 'APPEND' Cross-Site Scripting
CVE-2004-1100—webappscgi03 nov 2004
Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Goolery 0.3 - 'viewpic.php?conversation_id' Cross-Site Scripting
CVE-2004-2246—webappsphp02 nov 2004
Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebHost Automation Helm Control Panel 3.1.x - Multiple Input Validation Vulnerabilities
CVE-2004-1499—webappsasp02 nov 2004
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - IFRAME Tag Buffer Overflow
CVE-2004-1050—remotewindows02 nov 2004
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Goolery 0.3 - 'viewalbum.php?page' Cross-Site Scripting
CVE-2004-2245—webappsphp02 nov 2004
Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script
23RIESGO
abrir ↗
← anteriorpágina 510 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.