Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.407exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
CactuSoft CactuShop 5.0/5.1 - Cross-Site Scripting
CVE-2004-1882—webappsasp31 mar 2004
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Interchange 4.8.x/5.0 - Remote Information Disclosure
CVE-2004-0374—webappsasp30 mar 2004
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LinBit Technologies LINBOX Officeserver - Remote Authentication Bypass
CVE-2004-1878—webappscgi30 mar 2004
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a dire
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MPlayer 0.9/1.0 - Remote HTTP Header Buffer Overflow
CVE-2004-0386—doslinux30 mar 2004
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute ar
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebCT Campus Edition 3.8/4.x - HTML Injection
CVE-2004-1872—remotemultiple29 mar 2004
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alan Ward A-CART 2.0 - 'category.asp?catcode' SQL Injection (2)
CVE-2004-1873—webappsasp29 mar 2004
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fresh Guest Book 1.0/2.x - HTML Injection
CVE-2004-1867—webappscgi29 mar 2004
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PhotoPost PHP Pro 3.x/4.x - 'showgallery.php' Multiple SQL Injections
CVE-2004-1870—webappsphp29 mar 2004
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' pass
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ethereal 0.10.0 < 0.10.2 - IGAP Overflow
CVE-2004-0176—remotelinux28 mar 2004
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RealSecure / Blackice - 'iss_pam1.dll' Remote Overflow
CVE-2004-0362—remotewindows28 mar 2004
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eSignal 7.6 - STREAMQUOTE Remote Buffer Overflow
CVE-2004-1868—remotewindows26 mar 2004
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetSupport School 7.0/7.5 - Weak Password Encryption
CVE-2004-1861—locallinux26 mar 2004
Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ethereal - EIGRP Dissector TLV_IP_INT Long IP Remote Denial of Service
CVE-2004-0176—dosmultiple26 mar 2004
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NSTX 1.0/1.1 - Remote Denial of Service
CVE-2004-1866—doslinux26 mar 2004
nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, whi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - ASN.1 Remote (MS04-007)
CVE-2003-0818—remotewindows26 mar 2004
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NexGen FTP Server 1.0/2.x - Directory Traversal
CVE-2004-2487—remotewindows24 mar 2004
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Topic Calendar 1.0.1 - 'Calendar_Scheduler.php' Cross-Site Scripting
CVE-2005-0872—webappsphp24 mar 2004
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trend Micro Interscan VirusWall localweb - Directory Traversal
CVE-2004-1859—webappswindows24 mar 2004
Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PicoPhone Internet Phone 1.63 - Remote Buffer Overflow
CVE-2004-1854—doshardware24 mar 2004
Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - Arbitrary Command Execution
CVE-2004-1857—remotewindows24 mar 2004
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - setinfo.hts Script Directory Traversal
CVE-2004-1857—remotewindows24 mar 2004
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Web Jetadmin 7.5.2456 - Printer Firmware Update Script Arbitrary File Upload
CVE-2004-1856—remotewindows24 mar 2004
devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to up
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mythic Entertainment Dark Age of Camelot 1.6x - Encryption Key Signing
CVE-2004-1855—remotemultiple23 mar 2004
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 4.0.2 - ALLO Remote Buffer Overflow
CVE-2004-1883—remotewindows23 mar 2004
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Invision Power Services Invision Gallery 1.0.1 - Multiple SQL Injections
CVE-2004-1835—webappsphp23 mar 2004
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Solaris 2.6/7.0/8/9 - vfs_getvfssw function Privilege Escalation
CVE-2004-2686—localsolaris23 mar 2004
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
xweb 1.0 - Directory Traversal
CVE-2004-1838—remotelinux22 mar 2004
Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Invision Power Top Site List 1.0/1.1 - 'id' SQL Injection
CVE-2004-1836—webappsphp22 mar 2004
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Expinion.net News Manager Lite 2.5 - 'search.asp' Cross-Site Scripting
CVE-2004-1845—webappsasp20 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Expinion.net News Manager Lite 2.5 - 'more.asp?ID' SQL Injection
CVE-2004-1846—webappsasp20 mar 2004
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via
23RIESGO
abrir ↗
← anteriorpágina 529 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.