Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
NetSupport DNA HelpDesk 1.0 Problist Script - SQL Injection
CVE-2004-2737webappsasp21 jul 2004
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Internet Software Sciences Web+Center 4.0.1 - Cookie Object SQL Injection
CVE-2004-2561webappsasp21 jul 2004
Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
SCO Multi-channel Memorandum Distribution Facility - Multiple Vulnerabilities
CVE-2004-0511localsco20 jul 2004
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Medal of Honor - Remote Buffer Overflow (PoC)
CVE-2004-0735doswindows20 jul 2004
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RIESGO
abrir
Exploit-DBVexDay Proof
British National Corpus SARA - Remote Buffer Overflow
CVE-2004-1728dosmultiple20 jul 2004
Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the
23RIESGO
abrir
Exploit-DBVexDay Proof
SCI Photo Chat 3.4.9 - Cross-Site Scripting
CVE-2004-0673remotemultiple20 jul 2004
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Utility Manager All-in-One (MS04-019)
CVE-2004-0213localwindows20 jul 2004
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 1.3 - Comment HTML Injection
CVE-2004-0660webappsphp19 jul 2004
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RIESGO
abrir
Exploit-DBVexDay Proof
Outblaze Webmail - HTML Injection
CVE-2004-2625webappsphp19 jul 2004
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
Unreal Tournament 2004 - 'Secure' Remote Overflow (Metasploit)
CVE-2004-0608remotelinux18 jul 2004
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion Database Backup - Information Disclosure
CVE-2004-1724webappsphp18 jul 2004
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups direct
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Task Scheduler (XP/2000) - '.job' (MS04-022)
CVE-2004-0212localwindows18 jul 2004
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - 'address.html' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1719webappsphp17 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - address.html Full Path Disclosure
CVE-2004-1720webappsphp17 jul 2004
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - HTML Message Body Cross-Site Scripting
CVE-2004-1719webappsphp17 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - POSIX Subsystem Privilege Escalation (MS04-020)
CVE-2004-0213localwindows17 jul 2004
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - 'calendar.html?schedule' SQL Injection
CVE-2004-1722webappsphp17 jul 2004
SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - 'attachment.html?attachmentpage_text_error' Cross-Site Scripting
CVE-2004-1719webappsphp17 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Universal Language Utility Manager (MS04-019)
CVE-2004-0213localwindows17 jul 2004
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RIESGO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 7.4.5 - 'settings.html' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1719webappsphp17 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Gallery 1.4.4 - Remote Server-Side Script Execution
CVE-2004-1466webappsphp17 jul 2004
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds
23RIESGO
abrir
Exploit-DBVexDay Proof
RaXnet Cacti 0.6.x/0.8.x - 'Auth_Login.php' SQL Injection
CVE-2004-1737webappsphp16 jul 2004
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 1.3.1 - 'show_archives.php' Cross-Site Scripting
CVE-2004-0660webappsphp16 jul 2004
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0/2000 - POSIX Subsystem Local Buffer Overflow / Local Privilege Escalation (MS04-020)
CVE-2004-0210HIGHbajo ataquelocalwindows16 jul 2004
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain pa
71RIESGO
abrir
Exploit-DBVexDay Proof
Gattaca Server 2003 - Null Byte Full Path Disclosure
CVE-2004-2518webappscgi15 jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RIESGO
abrir
Exploit-DBVexDay Proof
Gattaca Server 2003 - 'web.tmpl?Language' CPU Consumption (Denial of Service)
CVE-2004-2519dosmultiple15 jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif
23RIESGO
abrir
Exploit-DBVexDay Proof
Gattaca Server 2003 - Cross-Site Scripting
CVE-2004-2522webappscgi15 jul 2004
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting
CVE-2004-1441webappscgi15 jul 2004
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Gattaca Server 2003 - 'Language' Path Exposure
CVE-2004-2518webappscgi15 jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RIESGO
abrir
Exploit-DBVexDay Proof
Gattaca Server 2003 POP3 - Denial of Service
CVE-2004-2520dosmultiple15 jul 2004
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio
23RIESGO
abrir
anteriorpágina 519 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.