Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Zone Spoofing (MS01-055)
CVE-2001-0664—remotewindows10 oct 2001
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain d
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Progress Database 8.3/9.1 - Multiple Buffer Overflows
CVE-2001-1127—localmultiple05 oct 2001
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AmTote Homebet - World Accessible Log
CVE-2001-1170—remotemultiple28 sep 2001
AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Amtote Homebet - Account Information Brute Force
CVE-2001-1528—remotemultiple28 sep 2001
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
3Com OfficeConnect DSL Router 812 1.1.7/840 1.1.7 - HTTP Port Router Denial of Service
CVE-2001-0740—doshardware21 sep 2001
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 4.3/4.4 - Login Capabilities Privileged File Reading
CVE-2001-1029—localfreebsd17 sep 2001
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 - File Information / Full Path Disclosure
CVE-2001-0986—remotewindows14 sep 2001
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as th
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 Apache - Remote Username Enumeration
CVE-2001-1013—remotelinux12 sep 2001
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EFTP 2.0.7 337 - Remote Buffer Overflow Code Execution / Denial of Service
CVE-2001-1112—remotewindows12 sep 2001
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EFTP Server 2.0.7.337 - Directory Existence / File Existence
CVE-2001-1109—remotewindows12 sep 2001
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Stalker Internet Mail Server 1.6 - Remote Buffer Overflow
CVE-1999-1504—remoteaix12 sep 2001
Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SpeechD 0.1/0.2 - Privileged Command Execution
CVE-2001-0956—localunix11 sep 2001
speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGIEmail 1.6 - Remote Buffer Overflow
CVE-2002-1652—remotelinux11 sep 2001
Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK MH_PROFILE Symbolic Link
CVE-2001-1092—localunix10 sep 2001
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hassan Consulting Shopping Cart 1.23 - Arbitrary Command Execution
CVE-2001-0985—remotecgi08 sep 2001
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metachar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Taylor UUCP 1.0.6 - Argument Handling Privilege Escalation
CVE-2001-0873—localunix08 sep 2001
uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privilege
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Power Up HTML 0.8033 Beta - Directory Traversal Arbitrary File Disclosure
CVE-2001-1138—remotecgi07 sep 2001
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Merit AAA RADIUS Server 3.8 - rlmadmin Symbolic Link
CVE-2001-1000—localunix07 sep 2001
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to re
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Digital Unix 4.0 - MSGCHK Buffer Overflow
CVE-2001-1093—localunix05 sep 2001
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (2)
CVE-2001-1067—remoteunix05 sep 2001
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary co
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Secure IDS 2.0/3.0 / Snort 1.x / ISS RealSecure 5/6 / NFR 5.0 - Encoded IIS Detection Evasion
CVE-2001-0669—remotemultiple05 sep 2001
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP-UX 11.0 - SWVerify Buffer Overflow
CVE-2001-0979—localhp-ux03 sep 2001
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Irix LPD tagprinter - Command Execution (Metasploit)
CVE-2001-0800—remoteirix01 sep 2001
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SIX-webboard 2.01 - File Retrieval
CVE-2001-1115—remotecgi31 ago 2001
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 LPD - Remote Command Execution
CVE-2001-1583—remotesolaris31 ago 2001
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Solaris 8.0 LPD - Command Execution (Metasploit)
CVE-2001-1583—remotesolaris31 ago 2001
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat 6.2/7.0/7.1 Lpd - Remote Command Execution via DVI Printfilter Configuration Error
CVE-2001-1002—remotelinux27 ago 2001
The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UltraEdit 8.2 - FTP Client Weak Password Encryption
CVE-2001-0983—localwindows23 ago 2001
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco CBOS 2.x - Multiple TCP Connection Denial of Service Vulnerabilities
CVE-2001-1064—doshardware23 ago 2001
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via mul
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Respondus for WebCT 1.1.2 - Weak Password Encryption
CVE-2001-1003—localmultiple23 ago 2001
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can rea
23RIESGO
abrir ↗
← anteriorpágina 585 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.