Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
SquirrelMail 1.2.6/1.2.7 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-1131—webappsphp19 sep 2002
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as othe
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trillian 0.6351/0.7x - Identd Buffer Overflow
CVE-2002-1486—remotewindows18 sep 2002
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (2)
CVE-2002-1492—localunix18 sep 2002
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (1)
CVE-2002-1492—localunix18 sep 2002
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - File Disclosure
CVE-2002-1483—remotemultiple17 sep 2002
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP requ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - Connection Proxy
CVE-2002-1484—remotemultiple17 sep 2002
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attem
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lycos HTMLGear - guestGear CSS HTML Injection
CVE-2002-1493—webappscgi17 sep 2002
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TCP SYN - 'bang.c' Denial of Service
CVE-1999-0116—dosbsd17 sep 2002
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WMNet2 1.0 6 - Kernel Memory File Descriptor Leakage
CVE-2002-1125—localfreebsd16 sep 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASCPU 0.60 Kernel - Memory File Descriptor Leakage
CVE-2002-1125—localunix16 sep 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BubbleMon 1.x Kernel - Memory File Descriptor Leakage
CVE-2002-1125—localunix16 sep 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WMMon 1.0 b2 - Memory Character File Open File Descriptor Read
CVE-2002-1125—localfreebsd16 sep 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PlanetWeb 1.14 - GET Buffer Overflow
CVE-2002-1489—doswindows16 sep 2002
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTT
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - Malformed Content-Length Denial of Service
CVE-2002-1828—doswindows13 sep 2002
Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negativ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - File Disclosure
CVE-2002-2145—remotewindows13 sep 2002
Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Enterasys SSR8000 SmartSwitch - Port Scan Denial of Service
CVE-2002-1501—doshardware13 sep 2002
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cau
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BRU 17.0 - XBRU Insecure Temporary File
CVE-2002-1512—locallinux13 sep 2002
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpGB 1.1 - HTML Injection
CVE-2002-1480—webappsphp09 sep 2002
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netris 0.3/0.4/0.5 - Remote Memory Corruption
CVE-2002-1566—remotelinux09 sep 2002
netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trillian Instant Messaging 0.x - Credential Encryption
CVE-2002-2162—localwindows09 sep 2002
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Tr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - IFrame/Frame Cross-Site/Zone Script Execution
CVE-2002-1187—remotewindows09 sep 2002
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execu
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpGB 1.x - SQL Injection
CVE-2002-1482—webappsphp09 sep 2002
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alleged Outlook Express 5/6 Link - Denial of Service
CVE-2002-2164—doswindows09 sep 2002
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (cra
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPGB 1.1/1.2 - PHP Code Injection
CVE-2002-1481—webappsphp09 sep 2002
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a den
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WoltLab Burning Board 2.0 - SQL Injection
CVE-2002-1505—webappsphp09 sep 2002
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AFD 1.2.x - Working Directory Local Buffer Overflow / Local Privilege Escalation
CVE-2002-1503—localunix04 sep 2002
Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aestiva HTML/OS 2.4 - Cross-Site Scripting
CVE-2002-1494—webappscgi03 sep 2002
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco VPN 3000 Series Concentrator Client - Authentication Denial of Service
CVE-2002-1101—doshardware03 sep 2002
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Super Site Searcher - Remote Command Execution
CVE-2002-2420—webappscgi03 sep 2002
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SWS Simple Web Server 0.0.3/0.0.4/0.1 - New Line Denial of Service
CVE-2002-2370—doslinux02 sep 2002
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request tha
23RIESGO
abrir ↗
← anteriorpágina 566 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.