Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.979exploits catalogados
37.614CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
CuteNews 0.88/1.3 - 'show_archives.php' Cross-Site Scripting
CVE-2004-0660webappsphp28 jun 2004
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 0.88/1.3 - 'example2.php' Cross-Site Scripting
CVE-2004-0660webappsphp28 jun 2004
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 0.88/1.3 - 'example1.php' Cross-Site Scripting
CVE-2004-0660webappsphp28 jun 2004
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in Cu
23RIESGO
abrir
Exploit-DBVexDay Proof
CGIScript.net CSFAQ 1.0 Script - Full Path Disclosure
CVE-2004-0665webappscgi28 jun 2004
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveal
23RIESGO
abrir
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - 'modules.php' Traversal Arbitrary Directory Listing
CVE-2004-0664webappsphp28 jun 2004
Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directorie
23RIESGO
abrir
Exploit-DBVexDay Proof
McMurtrey/Whitaker & Associates Cart32 2-5 GetLatestBuilds Script - Cross-Site Scripting
CVE-2004-0675webappscgi28 jun 2004
Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - Assembler Inline Function Local Denial of Service
CVE-2004-0554doslinux25 jun 2004
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an inf
23RIESGO
abrir
Exploit-DBVexDay Proof
CVS - Remote Entry Line Root Heap Overflow
CVE-2004-0396remotesolaris25 jun 2004
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows
35RIESGO
abrir
Exploit-DBVexDay Proof
Subversion 1.0.2 - 'svn_time_from_cstring()' Remote Overflow
CVE-2004-0397remotelinux25 jun 2004
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RIESGO
abrir
Exploit-DBVexDay Proof
CVS (Linux/FreeBSD) - Remote Entry Line Heap Overflow
CVE-2004-0396remotemultiple25 jun 2004
Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows
35RIESGO
abrir
Exploit-DBVexDay Proof
Rlpr 2.04 - 'msg()' Remote Format String
CVE-2004-0393remotelinux25 jun 2004
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitra
28RIESGO
abrir
Exploit-DBVexDay Proof
Borland Interbase 7.x - Remote Buffer Overflow
CVE-2004-2043remotelinux25 jun 2004
Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that us
28RIESGO
abrir
Exploit-DBVexDay Proof
ZaireWeb Solutions NewsLetter ZWS - Administrative Interface Authentication Bypass
CVE-2004-0621webappsphp24 jun 2004
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0.1 - 'newreply.php?WYSIWYG_HTML' Cross-Site Scripting
CVE-2004-0620webappsphp24 jun 2004
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD 4.10/5.x - 'execve()' Unaligned Memory Access Denial of Service
CVE-2004-0618dosfreebsd23 jun 2004
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call wi
23RIESGO
abrir
Exploit-DBVexDay Proof
BT Voyager 2000 Wireless ADSL Router - SNMP Community String Information Disclosure
CVE-2004-0616remotehardware22 jun 2004
The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obta
23RIESGO
abrir
Exploit-DBVexDay Proof
ArbitroWeb PHP Proxy 0.5/0.6 - Cross-Site Scripting
CVE-2004-0617webappsphp22 jun 2004
Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML vi
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link AirPlus DI-614+ / DI-624 / DI-704 - DHCP Log HTML Injection
CVE-2004-0615remotehardware21 jun 2004
Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router run
23RIESGO
abrir
Exploit-DBVexDay Proof
SqWebMail 4.0.4.20040524 - Email Header HTML Injection
CVE-2004-0591webappsphp21 jun 2004
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3
23RIESGO
abrir
Exploit-DBVexDay Proof
osTicket STS 1.2 - Attachment Remote Command Execution
CVE-2004-0613webappsphp21 jun 2004
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP reques
23RIESGO
abrir
Exploit-DBVexDay Proof
ircd-hybrid 7.0.1 / ircd-ratbox 1.5.1/2.0 - Socket Dequeuing Denial of Service
CVE-2004-0605doslinux19 jun 2004
Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox
23RIESGO
abrir
Exploit-DBVexDay Proof
Rlpr 2.0 - 'msg()' Multiple Vulnerabilities
CVE-2004-0393remotelinux19 jun 2004
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitra
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Enterprise Firewall 7.0/8.0 - DNSD DNS Cache Poisoning
CVE-2004-1754remotewindows15 jun 2004
The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via
23RIESGO
abrir
Exploit-DBVexDay Proof
phpHeaven phpMyChat 0.14.5 - 'admin.php3' Arbitrary File Access
CVE-2004-2717webappsphp15 jun 2004
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrativ
23RIESGO
abrir
Exploit-DBVexDay Proof
phpHeaven phpMyChat 0.14.5 - 'usersL.php3' Multiple SQL Injections
CVE-2004-2716webappsphp15 jun 2004
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
phpHeaven phpMyChat 0.14.5 - 'edituser.php3?do_not_login' Authentication Bypass
CVE-2004-2715webappsphp15 jun 2004
edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by
23RIESGO
abrir
Exploit-DBVexDay Proof
Linksys Web Camera Software 2.10 - 'Next_file' Cross-Site Scripting
CVE-2004-2508webappscgi14 jun 2004
Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 1.3 - 'SSI.php' Cross-Site Scripting
CVE-2004-2413webappsphp14 jun 2004
SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Virtual Programming VP-ASP Shoperror Script 4/5 - Cross-Site Scripting
CVE-2004-2411webappsasp14 jun 2004
The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.x - Multiple Input Validation Vulnerabilities
CVE-2004-2297webappsphp11 jun 2004
The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumpti
23RIESGO
abrir
anteriorpágina 521 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.