Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
QNX Photon input-cfg - '-s' Overflow
CVE-2004-1681dosunix13 sep 2004
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI f
23RIESGO
abrir
Exploit-DBVexDay Proof
BlackJumboDog FTP Server 3.6.1 - Remote Buffer Overflow
CVE-2004-1439remotewindows12 sep 2004
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
28RIESGO
abrir
Exploit-DBVexDay Proof
CDRecord's ReadCD - '$RSH exec()' SUID Shell Creation
CVE-2004-0806locallinux11 sep 2004
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache mod_ssl 2.0.x - Remote Denial of Service
CVE-2004-0751doslinux10 sep 2004
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows
45RIESGO
abrir
Exploit-DBVexDay Proof
Citadel/UX 6.23 - Remote USER Directive
CVE-2004-1705remotelinux09 sep 2004
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RIESGO
abrir
Exploit-DBVexDay Proof
Trillian 0.74i MSN Module - Remote Buffer Overflow
CVE-2004-1666remotewindows08 sep 2004
Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long strin
23RIESGO
abrir
Exploit-DBVexDay Proof
Call of Duty 1.4 - Denial of Service
CVE-2004-1664dosmultiple05 sep 2004
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2
23RIESGO
abrir
Exploit-DBVexDay Proof
PSNews 1.1 - 'No' Cross-Site Scripting
CVE-2004-1665webappsphp05 sep 2004
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Database Server 8.1.7/9.0.x - ctxsys.driload Access Validation
CVE-2004-0637remotemultiple03 sep 2004
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the
28RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 0.88/1.3.x - 'index.php' Cross-Site Scripting
CVE-2004-1659webappsphp02 sep 2004
Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Adminis
23RIESGO
abrir
Exploit-DBVexDay Proof
SiteCubed MailWorks Professional - Authentication Bypass
CVE-2004-1661webappsphp02 sep 2004
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "
23RIESGO
abrir
Exploit-DBVexDay Proof
Courier-IMAP 3.0.2-r1 - 'auth_debug()' Remote Format String
CVE-2004-0777remotebsd02 sep 2004
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when l
28RIESGO
abrir
Exploit-DBVexDay Proof
AOL Instant Messenger AIM - 'Away' Message Remote (2)
CVE-2004-0636remotewindows02 sep 2004
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.
50RIESGO
abrir
Exploit-DBVexDay Proof
Newtelligence DasBlog 1.x - Request Log HTML Injection
CVE-2004-1657webappsphp01 sep 2004
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM DB2 DTS To String Conversion - Denial of Service
CVE-2005-4869doslinux01 sep 2004
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application cra
23RIESGO
abrir
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.x/0.9.x Comment Module - 'CM_pid' Cross-Site Scripting
CVE-2004-1655webappsphp01 sep 2004
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
Comersus Cart 5.0 - HTTP Response Splitting
CVE-2004-1656webappsasp01 sep 2004
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM DB2 - Universal Database Information Disclosure
CVE-2005-4868localwindows01 sep 2004
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DCS-900 Camera - Remote IP Address Changer
CVE-2004-1650remotehardware31 ago 2004
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the
23RIESGO
abrir
Exploit-DBVexDay Proof
Web Animations Password Protect - Multiple Input Validation Vulnerabilities
CVE-2004-1647webappsasp31 ago 2004
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass a
23RIESGO
abrir
Exploit-DBVexDay Proof
Ground Control 1.0.0.7 - 'Server/Client' Denial of Service
CVE-2004-1751doswindows31 ago 2004
Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or se
23RIESGO
abrir
Exploit-DBVexDay Proof
Titan FTP Server - Long Command Heap Overflow
CVE-2004-1641remotewindows31 ago 2004
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) vi
38RIESGO
abrir
Exploit-DBVexDay Proof
WFTPD Pro Server 3.21 - MLST Remote Denial of Service
CVE-2004-1642doswindows31 ago 2004
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST
23RIESGO
abrir
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 5.0.x - CD Command Malformed File Path Remote Denial of Service
CVE-2004-1643doswindows30 ago 2004
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that cont
23RIESGO
abrir
Exploit-DBVexDay Proof
Citadel/UX - Remote Buffer Overflow
CVE-2004-1705remotelinux30 ago 2004
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RIESGO
abrir
Exploit-DBVexDay Proof
Nagl XOOPS Dictionary Module 1.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1640webappsphp28 ago 2004
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy File Sharing Web Server 1.25 - Denial of Service
CVE-2004-1744doswindows27 ago 2004
Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) v
23RIESGO
abrir
Exploit-DBVexDay Proof
Painkiller 1.3.1 - Denial of Service
CVE-2004-1745doswindows27 ago 2004
Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibl
23RIESGO
abrir
Exploit-DBVexDay Proof
Gaucho 1.4 - Mail Client Buffer Overflow
CVE-2004-1752remotewindows27 ago 2004
Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email w
23RIESGO
abrir
Exploit-DBVexDay Proof
Bird Chat 1.61 - Denial of Service
CVE-2004-1739doswindows_x8626 ago 2004
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
23RIESGO
abrir
anteriorpágina 515 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.