Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
Adam Webb NukeJokes 1.7/2.0 Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2007—webappsphp08 may 2004
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qualcomm Eudora 6.x - Embedded Hyperlink URI Obfuscation
CVE-2004-2649—remotewindows08 may 2004
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of char
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qualcomm Eudora 5.2.1/6.x - Embedded Hyperlink Buffer Overrun
CVE-2004-2005—doslinux07 may 2004
Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-m
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DeleGate 7.8.x/8.x - SSLway Filter Remote Stack Buffer Overflow (PoC)
CVE-2004-2003—doslinux06 may 2004
Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyWeb HTTP Server 3.3 - GET Buffer Overflow
CVE-2004-2614—remotewindows06 may 2004
Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Exim Sender 3.35 - Verification Remote Stack Buffer Overrun
CVE-2004-0399—remotelinux06 may 2004
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows rem
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - '/forums.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364—webappsphp05 may 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XChat 1.8.0/2.0.8 socks5 - Remote Buffer Overflow
CVE-2004-0409—remotelinux05 may 2004
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows re
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - '/images.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364—webappsphp05 may 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - '/page.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364—webappsphp05 may 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - '/user.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364—webappsphp05 may 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2363—webappsphp05 may 2004
Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allow
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPX 3.x - '/news.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364—webappsphp05 may 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Simple Machines Forum (SMF) 1.0 - Size Tag HTML Injection
CVE-2004-1996—webappsphp05 may 2004
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SurgeLDAP 1.0 - Web Administration Authentication Bypass
CVE-2004-2254—webappscgi05 may 2004
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
E-Zone Media FuzeTalk 2.0 - 'AddUser.cfm' Administrator Command Execution
CVE-2004-1995—webappscfm05 may 2004
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Titan FTP Server 3.0 - 'LIST' Denial of Service
CVE-2004-0437—doswindows04 may 2004
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
APSIS Pound 1.5 - Remote Format String
CVE-2004-2026—remotelinux03 may 2004
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Business Objects Crystal Reports 9/10 Web Form Viewer - Directory Traversal
CVE-2004-0204—remotewindows03 may 2004
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterpri
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PaX 2.6 Kernel Patch - Denial of Service
CVE-2004-1983—doslinux03 may 2004
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LHA 1.x - Remote Buffer Overflow / Directory Traversal
CVE-2005-0643—remoteunix30 abr 2004
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.2.2b - 'menu.inc.php' Cross-Site Scripting
CVE-2004-1985—webappsphp30 abr 2004
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Meta Data Foreign Domain Spoofing
CVE-2004-0763—remotewindows30 abr 2004
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Jav
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.2.2b - 'theme.php' Remote File Inclusion
CVE-2004-1989—webappsphp30 abr 2004
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SquirrelMail 1.4.x - Folder Name Cross-Site Scripting
CVE-2004-0519—webappsphp30 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary sc
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Moodle 1.1/1.2 - Cross-Site Scripting
CVE-2004-1978—webappsphp30 abr 2004
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HT
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.2.0 RC4 - 'init.inc.php' Remote File Inclusion
CVE-2004-1988—webappsphp30 abr 2004
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.2.0 RC4 - 'startdir' Traversal Arbitrary File Access
CVE-2004-1986—webappsphp30 abr 2004
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attacker
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - 'Lsasrv.dll' Remote Universal (MS04-011)
CVE-2003-0533—remotewindows29 abr 2004
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Siemens S55 - Cellular Telephone Sms Confirmation Message Bypass
CVE-2004-2626—remotehardware27 abr 2004
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SM
23RIESGO
abrir ↗
← anteriorpágina 524 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.