Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'NEWS_LOGIN?admin' Cookie Authentication Bypass
CVE-2004-1847webappsasp20 mar 2004
News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net Member Management System 2.1 - 'register.asp?err' Cross-Site Scripting
CVE-2004-1844webappsasp20 mar 2004
Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net Member Management System 2.1 - 'error.asp?err' Cross-Site Scripting
CVE-2004-1844webappsasp20 mar 2004
Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'category_news.asp?ID' SQL Injection
CVE-2004-1846webappsasp20 mar 2004
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'news_sort.asp?filter' SQL Injection
CVE-2004-1846webappsasp20 mar 2004
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'category_news_headline.asp' Cross-Site Scripting
CVE-2004-1845webappsasp20 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'search.asp' Cross-Site Scripting
CVE-2004-1845webappsasp20 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net Member Management System 2.1 - 'news_view.asp?ID' SQL Injection
CVE-2004-1843webappsasp20 mar 2004
SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID
23RIESGO
abrir
Exploit-DBVexDay Proof
Expinion.net News Manager Lite 2.5 - 'comment_add.asp' Cross-Site Scripting
CVE-2004-1845webappsasp20 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Eudora 6.0.3 (Windows) - Attachment Spoofing
CVE-2004-1521remotewindows19 mar 2004
Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Error Manager Module 2.1 - 'error.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1829webappsphp18 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Error Manager Module 2.1 - 'error.php?language' Full Path Disclosure
CVE-2004-1830webappsphp18 mar 2004
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Client Firewall Products 5 - 'SYMNDIS.SYS' Driver Remote Denial of Service
CVE-2004-0375doswindows18 mar 2004
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6/7 - HTTP webadmin.nsf Directory Traversal
CVE-2004-2311remotewindows17 mar 2004
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or deter
23RIESGO
abrir
Exploit-DBVexDay Proof
Belchior Foundry VCard 2.8 - Authentication Bypass
CVE-2004-1828webappsphp17 mar 2004
Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
WFTPD Server GUI 3.21 - Remote Denial of Service
CVE-2004-2367doswindows17 mar 2004
The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of se
23RIESGO
abrir
Exploit-DBVexDay Proof
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (2)
CVE-2004-0544localaix17 mar 2004
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) get
23RIESGO
abrir
Exploit-DBVexDay Proof
GlobalScape Secure FTP Server 2.0 Build 03.11.2004.2 - Site Command Remote Buffer Overflow
CVE-2004-2366doswindows17 mar 2004
Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6.5.1 - HTTP webadmin.nsf Quick Console Cross-Site Scripting
CVE-2004-2310remotewindows17 mar 2004
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.0/7.1 - Image Tag Admin Command Execution
CVE-2004-1842webappsphp16 mar 2004
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administra
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0 - 'showthread.php' Cross-Site Scripting
CVE-2004-1823webappsphp16 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0 - 'forumdisplay.php' Cross-Site Scripting
CVE-2004-1823webappsphp16 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Open Source 4.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1825webappsphp16 mar 2004
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Open Source 4.5 - 'index.php' SQL Injection
CVE-2004-1826webappsphp16 mar 2004
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Phorum 3.x - 'register.php' HTTP_REFERER Cross-Site Scripting
CVE-2004-1822webappsphp15 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
WarpSpeed 4nAlbum Module 0.92 - 'nmimage.php?z' Cross-Site Scripting
CVE-2004-1818webappsphp15 mar 2004
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
YABB SE 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1827webappsphp15 mar 2004
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
VocalTec VGW4/8 Telephony Gateway - Remote Authentication Bypass
CVE-2004-1813webappsasp15 mar 2004
VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trai
23RIESGO
abrir
Exploit-DBVexDay Proof
Phorum 3.x - 'profile.php?target' Cross-Site Scripting
CVE-2004-1822webappsphp15 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
WarpSpeed 4nAlbum Module 0.92 - 'modules.php?gid' SQL Injection
CVE-2004-1821webappsphp15 mar 2004
SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or p
23RIESGO
abrir
anteriorpágina 530 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.