Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (2)
CVE-2001-0876—remotewindows20 dic 2001
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (1)
CVE-2001-0876—remotewindows20 dic 2001
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Solaris /bin/login (SPARC/x86) - Remote Code Execution
CVE-2001-0797—remotelinux_sparc20 dic 2001
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alteon AceDirector - Half-Closed HTTP Request IP Address Revealing
CVE-2002-0209—remotehardware20 dic 2001
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZYXEL Prestige 681 SDSL Router - IP Fragment Reassembly
CVE-2001-1194—remotehardware18 dic 2001
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aktivate 1.0 3 - Shopping Cart Cross-Site Scripting
CVE-2001-1212—webappscgi18 dic 2001
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascrip
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
QPopper 4.0.x - PopAuth Trace File Shell Command Execution
CVE-2001-1487—remoteunix18 dic 2001
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Agora.CGI 3.x/4.0 - Debug Mode Cross-Site Scripting
CVE-2001-1199—webappscgi17 dic 2001
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
webmin 0.91 - Directory Traversal
CVE-2001-1196—remotecgi17 dic 2001
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Groupwise 5.5/6.0 Servlet Gateway - Default Authentication
CVE-2001-1195—remotenovell15 dic 2001
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
System V Derived /bin/login - Extraneous Arguments Buffer Overflow (modem based) (Metasploit)
CVE-2001-0797—remotesolaris12 dic 2001
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
CVE-2001-1490—dosmultiple11 dic 2001
Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
CVE-2001-1489—dosmultiple11 dic 2001
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Brian Dorricott MAILTO 1.0.7-9 - Unauthorized Mail Server Use
CVE-2001-1188—remotewindows11 dic 2001
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote server
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Denial of Service
CVE-2001-1518—doswindows11 dic 2001
RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denia
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Named Pipe Hijacking
CVE-2001-1519—localwindows11 dic 2001
RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then ca
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
CVE-2001-1491—dosmultiple11 dic 2001
Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - False Content-Length Field Denial of Service
CVE-2001-1186—doswindows11 dic 2001
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value t
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (1)
CVE-2001-0951—doswindows11 dic 2001
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.20.00 - Denial of Service
CVE-2001-1184—doswindows10 dic 2001
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.21.00 - Denial of Service
CVE-2001-1184—doswindows10 dic 2001
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 4.4 - AIO Library Cross Process Memory Write
CVE-2001-1185—localfreebsd10 dic 2001
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Volition Red Faction 1.0/1.1 - Game Server/Client Denial of Service
CVE-2001-0952—doswindows07 dic 2001
THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via pack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
McKesson Pathways Homecare 6.5 - Weak 'Username' and Password Encryption
CVE-2001-1546HIGHlocalwindows07 dic 2001
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by
41RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (2)
CVE-2001-0951—doswindows07 dic 2001
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZoneAlarm Pro 1.0/2.x - Outbound Packet Bypass
CVE-2001-1549—remotewindows06 dic 2001
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'user.php?uname' Cross-Site Scripting
CVE-2001-1524—webappsphp03 dic 2001
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'modules.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2001-1524—webappsphp03 dic 2001
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenBSD 2.x/3.0 - User Mode Return Value Denial of Service
CVE-2001-1559—dosopenbsd03 dic 2001
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EasyNews 1.5 - NewsDatabase/Template Modification
CVE-2001-1525—webappsphp01 dic 2001
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify n
23RIESGO
abrir ↗
← anteriorpágina 583 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.