Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Utility Manager Privilege Escalation (MS04-019)
CVE-2004-0213localwindows14 jul 2004
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4.x/5.0 - 'Strip_Tags()' Function Bypass
CVE-2004-0595remotephp14 jul 2004
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Remote Wscript.Shell
CVE-2004-0549remotewindows13 jul 2004
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6,
35RIESGO
abrir
Exploit-DBVexDay Proof
IBM Lotus Notes 6.0/6.5 - Multiple Java Applet Vulnerabilities
CVE-2004-2280dosunix13 jul 2004
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial o
23RIESGO
abrir
Exploit-DBVexDay Proof
Moodle Help Script 1.x - Cross-Site Scripting
CVE-2004-0725webappsphp13 jul 2004
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
IM-Switch - Insecure Temporary File Handling Symbolic Link
CVE-2004-2502locallinux13 jul 2004
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Browser 0.9/1.x Cache File - Multiple Vulnerabilities
CVE-2004-0760remotewindows13 jul 2004
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null charact
23RIESGO
abrir
Exploit-DBVexDay Proof
WebSTAR FTP Server 5.3.2 (OSX) - USER Overflow (Metasploit)
CVE-2004-0695remoteosx13 jul 2004
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RIESGO
abrir
Exploit-DBVexDay Proof
Norton AntiVirus - Denial of Service
CVE-2004-0683doswindows12 jul 2004
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a com
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - JavaScript Method Assignment Cross-Domain Scripting
CVE-2004-0727remotewindows12 jul 2004
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows
35RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.x - 'viewtopic.php' PHP Script Injection
CVE-2004-1315webappsphp12 jul 2004
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RIESGO
abrir
Exploit-DBVexDay Proof
Code-Crafters Ability Mail Server 1.18 - 'errormsg' Cross-Site Scripting
CVE-2004-2494remotemultiple12 jul 2004
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Popup.show Mouse Event Hijacking
CVE-2004-0841remotewindows12 jul 2004
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.sho
35RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 4.1/5.0 - Zero-Length Password Authentication Bypass
CVE-2004-0627remotemultiple10 jul 2004
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication v
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Remote Application.Shell
CVE-2004-2291remotewindows09 jul 2004
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla 1.7 - External Protocol Handler
CVE-2004-0648remotewindows08 jul 2004
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Style Tag Comment Memory Corruption
CVE-2004-0842remotewindows08 jul 2004
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service
35RIESGO
abrir
Exploit-DBVexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_gatewayPayPal.asp' Price Manipulation
CVE-2004-0682webappsasp07 jul 2004
comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to c
23RIESGO
abrir
Exploit-DBVexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site Scripting
CVE-2004-0681webappsasp07 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffic
23RIESGO
abrir
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - Cookie Manipulation Authentication Bypass
CVE-2004-2443webappsphp06 jul 2004
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie se
23RIESGO
abrir
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - 'action' Cross-Site Scripting
CVE-2004-2444webappsphp06 jul 2004
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - 'gadget' Traversal Arbitrary File Access
CVE-2004-2445webappsphp06 jul 2004
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..
23RIESGO
abrir
Exploit-DBVexDay Proof
Fastream NETFile FTP/Web Server 6.5/6.7 - Directory Traversal
CVE-2004-0676webappscgi05 jul 2004
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to c
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure
CVE-2004-0671webappscgi05 jul 2004
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t
23RIESGO
abrir
Exploit-DBVexDay Proof
12Planet Chat Server 2.9 - Cross-Site Scripting
CVE-2004-0678remotemultiple05 jul 2004
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
MPlayer 1.0pre4 GUI - Filename handling Overflow
CVE-2004-0659remotelinux04 jul 2004
Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code v
28RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 2.5.7 - Remote code Injection
CVE-2004-2631webappsphp04 jul 2004
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Netegrity IdentityMinder Web Edition 5.6 - Null Byte Cross-Site Scripting
CVE-2004-0672webappscgi01 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi
23RIESGO
abrir
Exploit-DBVexDay Proof
Netegrity IdentityMinder Web Edition 5.6 - Management Interface Cross-Site Scripting
CVE-2004-0672webappscgi01 jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino Server 6 - Web Access Remote Denial of Service
CVE-2004-0668dosunix30 jun 2004
Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail
23RIESGO
abrir
anteriorpágina 520 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.