Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Epic Games Unreal Engine 436 - Client Unreal URL Denial of Service
CVE-2003-1431dosmultiple05 feb 2003
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash
23RIESGO
abrir
Exploit-DBVexDay Proof
ByteCatcher FTP Client 1.0.4 - 'Server Banner' Buffer Overflow
CVE-2003-1369doswindows04 feb 2003
Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibl
23RIESGO
abrir
Exploit-DBVexDay Proof
Electrasoft 32Bit FTP 9.49.1 - Client Long Server Banner Buffer Overflow
CVE-2003-1368doswindows04 feb 2003
Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly
23RIESGO
abrir
Exploit-DBVexDay Proof
TOPO 1.41 - Full Path Disclosure
CVE-2003-1409webappsphp04 feb 2003
TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter t
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPMyShop 1.0 - 'compte.php' SQL Injection
CVE-2003-1532webappsphp03 feb 2003
SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 5.x/6.0 - Avatar HTML Injection
CVE-2003-1400webappsphp03 feb 2003
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD 2.x/3.x - CHPass Temporary File Link File Content Revealing
CVE-2003-1366localopenbsd03 feb 2003
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a tem
23RIESGO
abrir
Exploit-DBVexDay Proof
Sambar Server 5.x - Open Proxy / Authentication Bypass
CVE-2003-1286remotewindows30 ene 2003
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Nukebrowser 2.x - Remote File Inclusion
CVE-2003-1436webappsphp30 ene 2003
PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
BitchX 1.0 - 'RPL_NAMREPLY' Denial of Service
CVE-2003-1450doslinux30 ene 2003
BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Solaris 2.5/2.6/7.0/8/9 AT Command - Arbitrary File Deletion
CVE-2003-1073localsolaris27 ene 2003
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r arg
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 3.x - Null Byte Directory / File Disclosure
CVE-2003-0042remotelinux26 ene 2003
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with
35RIESGO
abrir
Exploit-DBVexDay Proof
FTLS Guestbook 1.1 - Script Injection
CVE-2003-1348webappsphp25 ene 2003
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.1 - Error Page Cross-Site Scripting
CVE-2003-0038webappscgi24 ene 2003
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RIESGO
abrir
Exploit-DBVexDay Proof
slocate 2.5/2.6 - Local Buffer Overrun
CVE-2003-0056doslinux24 ene 2003
Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.1 - 'email' Cross-Site Scripting
CVE-2003-0038webappscgi24 ene 2003
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RIESGO
abrir
Exploit-DBVexDay Proof
List Site Pro 2.0 - User Database Delimiter Injection
CVE-2003-1350remotemultiple24 ene 2003
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field de
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Locator Service Buffer Overflow
CVE-2003-0003remotewindows22 ene 2003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
MTink 0.9.x - Printer Status Monitor Environment Variable Buffer Overflow
CVE-2003-0034locallinux21 ene 2003
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local
23RIESGO
abrir
Exploit-DBVexDay Proof
CVS 1.11.x - Directory Request Double-Free Heap Corruption
CVE-2003-0015remotelinux20 ene 2003
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly ex
28RIESGO
abrir
Exploit-DBVexDay Proof
GameSpy 3D 2.62 - Packet Amplification Denial of Service
CVE-2003-1354doslinux17 ene 2003
Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.3 - 'privmsg.php' SQL Injection
CVE-2003-1530webappsphp17 ene 2003
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Virus Control System 1.8 - Information Disclosure
CVE-2003-1344remotewindows15 ene 2003
Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords,
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 3.x - CGI Directory Insufficient Permissions
CVE-2003-1341remotewindows15 ene 2003
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentica
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro ScanMail For Exchange 3.8 - Authentication Bypass
CVE-2003-1343remotewindows15 ene 2003
Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Virus Control System 1.8 - Denial of Service
CVE-2003-1342doswindows15 ene 2003
Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memor
23RIESGO
abrir
Exploit-DBVexDay Proof
GLIBC locale - Format Strings
CVE-2000-0844locallinux15 ene 2003
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'profiles.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2003-1347webappsphp14 ene 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'comment.php?cid' Cross-Site Scripting
CVE-2003-1347webappsphp14 ene 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'Homepage User' HTML Injection
CVE-2003-1347webappsphp14 ene 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
anteriorpágina 558 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.