Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.439exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
LPRng (RedHat 7.0) - 'lpd' Format String
CVE-2000-0917—remotelinux11 dic 2000
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
University of Washington Pico 3.x/4.x - File Overwrite
CVE-2001-0736—locallinux11 dic 2000
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to ove
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Leif M. Wright simplestmail.cgi 1.0 - Remote Command Execution
CVE-2001-0024—remotecgi11 dic 2000
simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacte
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Leif M. Wright everythingform.cgi 2.0 - Arbitrary Command Execution
CVE-2001-0023—remotecgi11 dic 2000
everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharac
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ssldump 0.9 b1 - Format String
CVE-2001-0032—remoteunix11 dic 2000
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 - Roaring Penguin PPPoE Denial of Service
CVE-2001-0026—doslinux11 dic 2000
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet wit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Leif M. Wright - 'ad.cgi' 1.0 Unchecked Input
CVE-2001-0025—remotecgi11 dic 2000
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KTH Kerberos 4 - Arbitrary Proxy Usage
CVE-2001-0034—remotemultiple08 dic 2000
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Watchguard SOHO 2.2 - Denial of Service
CVE-2001-0049—doshardware08 dic 2000
WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GE
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oops Proxy Server 1.4.22 - Remote Buffer Overflow (2)
CVE-2001-0028—remotelinux07 dic 2000
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MetaProducts Offline Explorer 1.x - FileSystem Disclosure
CVE-2001-0038—remotewindows07 dic 2000
Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive le
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
keware technologies homeseer 1.4 - Directory Traversal
CVE-2001-0037—remotewindows07 dic 2000
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 + PHP 3 - File Disclosure
CVE-2001-0042—remotemultiple06 dic 2000
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack contai
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Endymion MailMan 3.0.x - Arbitrary Command Execution
CVE-2001-0021—remoteunix06 dic 2000
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 3.0.16/4.0.2 - Remote Format Overflow
CVE-2000-0967—remotelinux06 dic 2000
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary com
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Catalyst 4000 4.x/5.x / Catalyst 5000 4.5/5.x / Catalyst 6000 5.x - Memory Leak Denial of Service
CVE-2001-0041—doshardware06 dic 2000
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM DB2 - Universal Database for Linux 6.1/Windows NT 6.1 Known Default Password
CVE-2001-0051—remotemultiple05 dic 2000
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM DB2 - Universal Database for Windows NT 6.1/7.1 SQL Denial of Service
CVE-2001-0052—doswindows05 dic 2000
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cat Soft Serv-U FTP Server 2.4/2.5 - FTP Directory Traversal
CVE-2001-0054—remotewindows05 dic 2000
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Phonebook Server Buffer Overflow
CVE-2000-1089—remotewindows04 dic 2000
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Se
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UUCP - File Creation/Overwriting Symlinks
CVE-2000-1134—locallinux04 dic 2000
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BitchX IRC Client 1.0 c17 - DNS Buffer Overflow
CVE-2001-0050—remoteunix04 dic 2000
Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GLIBC locale - bug mount
CVE-2000-0844—locallinux02 dic 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
dislocate 1.3 - Local i386
CVE-2001-0066—locallinux02 dic 2000
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset valu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'Jolt2.c' Denial of Service (MS00-029)
CVE-2000-0305—doswindows02 dic 2000
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a den
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x - '/usr/lib/lpd/piobe' Local Buffer Overflow
CVE-2000-1124—localaix01 dic 2000
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM AIX 4.3 - '/usr/lib/lpd/digest' Local Buffer Overflow
CVE-2000-1120—localaix01 dic 2000
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server 7.0/2000 / Data Engine 1.0/2000 - xp_displayparamstmt Buffer Overflow
CVE-2000-1081—localwindows01 dic 2000
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - 'INPUT TYPE=FILE' Remote File Upload
CVE-2001-0089—remotewindows01 dic 2000
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE ele
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM AIX 4.x - '/usr/bin/setsenv' Local Buffer Overflow
CVE-2000-1119—localaix01 dic 2000
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a l
23RIESGO
abrir ↗
← anteriorpágina 600 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.