Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Siemens S55 - Cellular Telephone Sms Confirmation Message Bypass
CVE-2004-2626remotehardware27 abr 2004
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SM
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 7.2 Multiple Video Gallery Module - SQL Injection
CVE-2004-1972webappsphp26 abr 2004
SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'index.php?redirect' Cross-Site Scripting
CVE-2004-1965webappsphp26 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote atta
38RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'board.php?FID' SQL Injection
CVE-2004-1966webappsphp26 abr 2004
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'myhome.php?to' Cross-Site Scripting
CVE-2004-1965webappsphp26 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote atta
38RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'member.php' Multiple SQL Injections
CVE-2004-1966webappsphp26 abr 2004
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - Private Message Disclosure
CVE-2004-1968webappsphp26 abr 2004
The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'member.php?redirect' Cross-Site Scripting
CVE-2004-1965webappsphp26 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote atta
38RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'search.php?q' SQL Injection
CVE-2004-1966webappsphp26 abr 2004
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'post.php' Multiple SQL Injections
CVE-2004-1966webappsphp26 abr 2004
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBB 1.0.x - 'post.php?TID' Cross-Site Scripting
CVE-2004-1965webappsphp26 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote atta
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Shell Long Share Name Buffer Overrun
CVE-2004-0214doswindows25 abr 2004
Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'Lsasrv.dll' RPC Remote Buffer Overflow (MS04-011)
CVE-2003-0533remotewindows24 abr 2004
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority
60RIESGO
abrir
Exploit-DBVexDay Proof
PHProfession 2.5 - 'modules.php?offset' SQL Injection
CVE-2004-1955webappsphp23 abr 2004
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via
23RIESGO
abrir
Exploit-DBVexDay Proof
PHProfession 2.5 - 'modules.php?jcode' Cross-Site Scripting
CVE-2004-1954webappsphp23 abr 2004
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Protector System 1.15 b1 - 'index.php' SQL Injection
CVE-2004-1962webappsphp23 abr 2004
SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filt
23RIESGO
abrir
Exploit-DBVexDay Proof
TCP Connection Reset - Remote Denial of Service
CVE-2004-0230doslinux23 abr 2004
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial o
45RIESGO
abrir
Exploit-DBVexDay Proof
PHProfession 2.5 - 'upload.php' Direct Request Full Path Disclosure
CVE-2004-1953webappsphp23 abr 2004
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which re
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple Vendor - TCP Sequence Number Approximation (4)
CVE-2004-0230remotemultiple23 abr 2004
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial o
45RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.5.x/2.6.x - CPUFreq Proc Handler Integer Handling Memory Read
CVE-2004-0228locallinux23 abr 2004
Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain pr
23RIESGO
abrir
Exploit-DBVexDay Proof
Protector System 1.15 - 'blocker_query.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1960webappsphp23 abr 2004
Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
Advanced Guestbook 2.2 - 'Password' SQL Injection
CVE-2004-1952webappsphp23 abr 2004
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain
23RIESGO
abrir
Exploit-DBVexDay Proof
Omnicron OmniHTTPd 2.x/3.0 - GET Buffer Overflow
CVE-2004-2299remotewindows23 abr 2004
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET
28RIESGO
abrir
Exploit-DBVexDay Proof
Epic Games Unreal Tournament Engine 3 - UMOD Manifest.INI Arbitrary File Overwrite
CVE-2004-1958remotemultiple22 abr 2004
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files
23RIESGO
abrir
Exploit-DBVexDay Proof
Xine 0.9.x and Xine-Lib 1 - Multiple Remote File Overwrite Vulnerabilities
CVE-2004-1951remotelinux22 abr 2004
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000 - TCP Connection Reset
CVE-2004-0230doswindows22 abr 2004
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial o
45RIESGO
abrir
Exploit-DBVexDay Proof
PostNuke Phoenix 0.726 - 'openwindow.php?hlpfile' Cross-Site Scripting
CVE-2004-1957webappsphp21 abr 2004
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - SSL Remote Buffer Overflow (MS04-011)
CVE-2003-0719remotewindows21 abr 2004
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as u
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.3 - 'setsockopt' Local Denial of Service
CVE-2004-0424doslinux21 abr 2004
Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows loca
23RIESGO
abrir
Exploit-DBVexDay Proof
SquirrelMail - 'chpasswd' Local Buffer Overflow
CVE-2004-0524locallinux20 abr 2004
Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local us
23RIESGO
abrir
anteriorpágina 525 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.