Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Cactusoft CactuShop 5.0/5.1 - SQL Injection
CVE-2004-1881webappsasp31 mar 2004
SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
Interchange 4.8.x/5.0 - Remote Information Disclosure
CVE-2004-0374webappsasp30 mar 2004
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensi
23RIESGO
abrir
Exploit-DBVexDay Proof
LinBit Technologies LINBOX Officeserver - Remote Authentication Bypass
CVE-2004-1878webappscgi30 mar 2004
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a dire
23RIESGO
abrir
Exploit-DBVexDay Proof
MPlayer 0.9/1.0 - Remote HTTP Header Buffer Overflow
CVE-2004-0386doslinux30 mar 2004
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute ar
28RIESGO
abrir
Exploit-DBVexDay Proof
PhotoPost PHP Pro 3.x/4.x - 'showgallery.php' Multiple SQL Injections
CVE-2004-1870webappsphp29 mar 2004
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' pass
23RIESGO
abrir
Exploit-DBVexDay Proof
Alan Ward A-CART 2.0 - 'category.asp?catcode' SQL Injection (2)
CVE-2004-1873webappsasp29 mar 2004
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via
23RIESGO
abrir
Exploit-DBVexDay Proof
Fresh Guest Book 1.0/2.x - HTML Injection
CVE-2004-1867webappscgi29 mar 2004
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
WebCT Campus Edition 3.8/4.x - HTML Injection
CVE-2004-1872remotemultiple29 mar 2004
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Ethereal 0.10.0 < 0.10.2 - IGAP Overflow
CVE-2004-0176remotelinux28 mar 2004
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RIESGO
abrir
Exploit-DBVexDay Proof
RealSecure / Blackice - 'iss_pam1.dll' Remote Overflow
CVE-2004-0362remotewindows28 mar 2004
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RIESGO
abrir
Exploit-DBVexDay Proof
NetSupport School 7.0/7.5 - Weak Password Encryption
CVE-2004-1861locallinux26 mar 2004
Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - ASN.1 Remote (MS04-007)
CVE-2003-0818remotewindows26 mar 2004
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RIESGO
abrir
Exploit-DBVexDay Proof
eSignal 7.6 - STREAMQUOTE Remote Buffer Overflow
CVE-2004-1868remotewindows26 mar 2004
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Ethereal - EIGRP Dissector TLV_IP_INT Long IP Remote Denial of Service
CVE-2004-0176dosmultiple26 mar 2004
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RIESGO
abrir
Exploit-DBVexDay Proof
NSTX 1.0/1.1 - Remote Denial of Service
CVE-2004-1866doslinux26 mar 2004
nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, whi
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Web Jetadmin 7.5.2456 - Printer Firmware Update Script Arbitrary File Upload
CVE-2004-1856remotewindows24 mar 2004
devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to up
28RIESGO
abrir
Exploit-DBVexDay Proof
NexGen FTP Server 1.0/2.x - Directory Traversal
CVE-2004-2487remotewindows24 mar 2004
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Web Jetadmin 7.5.2456 - Arbitrary Command Execution
CVE-2004-1857remotewindows24 mar 2004
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RIESGO
abrir
Exploit-DBVexDay Proof
Topic Calendar 1.0.1 - 'Calendar_Scheduler.php' Cross-Site Scripting
CVE-2005-0872webappsphp24 mar 2004
Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows r
23RIESGO
abrir
Exploit-DBVexDay Proof
PicoPhone Internet Phone 1.63 - Remote Buffer Overflow
CVE-2004-1854doshardware24 mar 2004
Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Web Jetadmin 7.5.2456 - setinfo.hts Script Directory Traversal
CVE-2004-1857remotewindows24 mar 2004
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
45RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Interscan VirusWall localweb - Directory Traversal
CVE-2004-1859webappswindows24 mar 2004
Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Mythic Entertainment Dark Age of Camelot 1.6x - Encryption Key Signing
CVE-2004-1855remotemultiple23 mar 2004
Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers
23RIESGO
abrir
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 4.0.2 - ALLO Remote Buffer Overflow
CVE-2004-1883remotewindows23 mar 2004
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Services Invision Gallery 1.0.1 - Multiple SQL Injections
CVE-2004-1835webappsphp23 mar 2004
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Solaris 2.6/7.0/8/9 - vfs_getvfssw function Privilege Escalation
CVE-2004-2686localsolaris23 mar 2004
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load ar
23RIESGO
abrir
Exploit-DBVexDay Proof
xweb 1.0 - Directory Traversal
CVE-2004-1838remotelinux22 mar 2004
Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Top Site List 1.0/1.1 - 'id' SQL Injection
CVE-2004-1836webappsphp22 mar 2004
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'search.asp' Cross-Site Scripting
CVE-2004-1845webappsasp20 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'more.asp?ID' SQL Injection
CVE-2004-1846webappsasp20 mar 2004
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via
23RIESGO
abrir
anteriorpágina 529 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.