Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Windows XP/2000 - showHelp '.CHM' File Execution (MS03-004)
CVE-2003-1041doswindows30 dic 2003
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal a
35RIESGO
abrir
Exploit-DBVexDay Proof
XSOK 1.0 2 - 'LANG Environment' Local Buffer Overrun
CVE-2004-0074locallinux30 dic 2003
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RIESGO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (2)
CVE-2003-1200remotewindows29 dic 2003
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RIESGO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (1)
CVE-2003-1200doswindows29 dic 2003
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - Failure To Log Undocumented TRACK Requests
CVE-2003-1566remotewindows29 dic 2003
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote a
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (1)
CVE-2003-1307locallinux26 dic 2003
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (2)
CVE-2003-1307locallinux26 dic 2003
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RIESGO
abrir
Exploit-DBVexDay Proof
KnowledgeBuilder 2.0/2.1/3.0 - Remote File Inclusion
CVE-2003-1131webappsphp24 dic 2003
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 6.x - 'Category' SQL Injection
CVE-2004-0269webappsphp23 dic 2003
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera Browser 6.0 6 - URI Display Obfuscation
CVE-2003-1025remotewindows23 dic 2003
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.6 - 'privmsg.php' Cross-Site Scripting
CVE-2004-2130webappsphp23 dic 2003
Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.6 - 'search_id' SQL Injection / MD5 Hash
CVE-2003-1216webappsphp21 dic 2003
SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL a
23RIESGO
abrir
Exploit-DBVexDay Proof
Tcpdump 3.x - L2TP Parser Remote Denial of Service
CVE-2003-1029doslinux20 dic 2003
The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loo
23RIESGO
abrir
Exploit-DBVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow Universal
CVE-2003-1339remotewindows18 dic 2003
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - 'osCsid' Cross-Site Scripting
CVE-2003-1219webappsphp17 dic 2003
Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3
23RIESGO
abrir
Exploit-DBVexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (2)
CVE-2003-1030remotewindows16 dic 2003
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Exploit-DBVexDay Proof
HP-UX B11.11 - '/usr/bin/ct' Format String Privilege Escalation
CVE-2003-0090localhp-ux16 dic 2003
20RIESGO
abrir
Exploit-DBVexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (1)
CVE-2003-1030remotewindows16 dic 2003
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Exploit-DBVexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (3)
CVE-2003-1030remotewindows16 dic 2003
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Messenger Service (French) - Remote (MS03-043)
CVE-2003-0717remotewindows16 dic 2003
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10 - CD9660.Util Probe For Mounting Argument Local Buffer Overflow
CVE-2003-1006dososx15 dic 2003
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 1.2.1 - URI Display Obfuscation (1)
CVE-2003-1025remotewindows09 dic 2003
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 1.2.1 - URI Display Obfuscation (2)
CVE-2003-1025remotewindows09 dic 2003
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir
Exploit-DBVexDay Proof
LaGarde StoreFront 5.0 Shopping Cart - 'login.asp' SQL Injection
CVE-2003-0557webappsasp07 dic 2003
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to o
23RIESGO
abrir
Exploit-DBVexDay Proof
FVWM 2.4/2.5 - fvwm-menu-Directory Command Execution
CVE-2003-1308locallinux05 dic 2003
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local us
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.22 - 'do_brk()' Local Privilege Escalation (2)
CVE-2003-0961locallinux05 dic 2003
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Workstation Service Remote (MS03-049)
CVE-2003-0812remotewindows04 dic 2003
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.22 - 'do_brk()' Local Privilege Escalation (1)
CVE-2003-0961locallinux02 dic 2003
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to
23RIESGO
abrir
Exploit-DBVexDay Proof
Applied Watch Command Center 1.0 - Authentication Bypass (1)
CVE-2003-0974remotemultiple28 nov 2003
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as
23RIESGO
abrir
Exploit-DBVexDay Proof
Applied Watch Command Center 1.0 - Authentication Bypass (2)
CVE-2003-0974remotemultiple28 nov 2003
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as
23RIESGO
abrir
anteriorpágina 539 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.