Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.366exploits catalogados
37.872CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'eid' SQL Injection
CVE-2004-1914—webappsphp08 abr 2004
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execut
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KPhone 2.x/3.x/4.0.1 - Malformed STUN Packet Denial of Service
CVE-2004-1940—dosmultiple08 abr 2004
sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN respon
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1st Class Mail Server 4.0 1 - Index Cross-Site Scripting
CVE-2004-2447—webappscgi08 abr 2004
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'block-calendar.php' Full Path Disclosure
CVE-2004-1912—webappsphp08 abr 2004
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'block-Calendar1.php' Full Path Disclosure
CVE-2004-1912—webappsphp08 abr 2004
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1st Class Mail Server 4.0 1 - viewmail.tagz Cross-Site Scripting
CVE-2004-2447—webappscgi08 abr 2004
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'eid' Cross-Site Scripting
CVE-2004-1913—webappsphp08 abr 2004
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1st Class Mail Server 4.0 1 - list.tagz Cross-Site Scripting
CVE-2004-2447—webappscgi08 abr 2004
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1st Class Mail Server 4.0 1 - general.tagz Cross-Site Scripting
CVE-2004-2447—webappscgi08 abr 2004
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1st Class Mail Server 4.0 1 - advanced.tagz Cross-Site Scripting
CVE-2004-2447—webappscgi08 abr 2004
Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
lcdproc lcdd 0.x/4.x - Multiple Vulnerabilities
CVE-2004-1915—remotelinux08 abr 2004
Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execut
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'modules.php' Full Path Disclosure
CVE-2004-1912—webappsphp08 abr 2004
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeCalendar 1.1.a - 'block-Calendar_center.php' Full Path Disclosure
CVE-2004-1912—webappsphp08 abr 2004
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AzDGDatingLite 2.1.1 - 'index.php?language' Cross-Site Scripting
CVE-2004-1911—webappsphp07 abr 2004
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Security Check Virus Detection - COM Object Denial of Service
CVE-2004-1910—doswindows07 abr 2004
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mcafee FreeScan CoMcFreeScan Browser - Object Buffer Overflow (PoC)
CVE-2004-1906—doswindows07 abr 2004
Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AzDGDatingLite 2.1.1 - 'view.php?id' Cross-Site Scripting
CVE-2004-1911—webappsphp07 abr 2004
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mcafee FreeScan CoMcFreeScan Browser - Information Disclosure
CVE-2004-1908—remotewindows07 abr 2004
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 4.0.x - Web Filtering Remote Denial of Service
CVE-2004-1907—doswindows07 abr 2004
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blaxxun Contact 3D - X-CC3D Browser Object Buffer Overflow (PoC)
CVE-2004-1903—doswindows06 abr 2004
Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an ob
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Panda ActiveScan 5.0 - 'ascontrol.dll' Remote Heap Overflow
CVE-2004-1904—doswindows06 abr 2004
Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Inter
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
tcpdump - ISAKMP Identification Payload Integer Overflow
CVE-2004-0184—remotelinux05 abr 2004
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of serv
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ada imgsvr 0.4 - Directory Traversal
CVE-2004-2464—remotewindows05 abr 2004
Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or li
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aborior Encore Web Forum - Arbitrary Command Execution
CVE-2004-1888—webappscgi03 abr 2004
display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - ARP Table Entries Denial of Service
CVE-2007-1531—doswindows02 abr 2004
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ADA IMGSVR 0.4 - Arbitrary File Download
CVE-2004-1887—remotewindows01 abr 2004
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ADA IMGSVR 0.4 - Remote Directory Listing
CVE-2004-1887—remotewindows01 abr 2004
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Roger Wilco Server 1.4.1 - Unauthorized Audio Stream Denial of Service
CVE-2004-2451—dosmultiple31 mar 2004
Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Roger Wilco Server 1.4.1 - UDP Datagram Handling Denial of Service
CVE-2004-2449—dosmultiple31 mar 2004
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CactuSoft CactuShop 5.0/5.1 - Cross-Site Scripting
CVE-2004-1882—webappsasp31 mar 2004
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbit
23RIESGO
abrir ↗
← anteriorpágina 528 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.