Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
FreeBSD 3.5/4.x - '/usr/bin/top' Format String
CVE-2000-0998—localfreebsd01 nov 2000
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" fun
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 2.0.7 - SWAT Symlink (2)
CVE-2000-0935—locallinux01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 2.0.7 - SWAT Logging Failure
CVE-2000-0937—remoteunix01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Unify eWave ServletExec 3.0 c - Denial of Service
CVE-2000-1025—dosmultiple30 oct 2000
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kootenay Web Inc whois 1.0 - Remote Command Execution
CVE-2000-0941—remotecgi29 oct 2000
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cat Soft Serv-U FTP Server 2.5.x - Brute Force
CVE-2000-1033—remotewindows29 oct 2000
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (poss
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Indexing Service (Windows 2000/NT 4.0) - '.htw' Cross-Site Scripting
CVE-2000-0942—remotewindows28 oct 2000
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross s
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ISC BIND 8.1 - Host Remote Buffer Overflow
CVE-2000-1029—remoteunix27 oct 2000
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR qu
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Virtual Central Office 4000 (VCO/4K) 5.1.3 - Remote Username / Password Retrieval
CVE-2000-0955—remotehardware26 oct 2000
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Catalyst 3500 XL - Arbitrary Command Execution
CVE-2000-0945—remotehardware26 oct 2000
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands with
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco IOS 12 - Software '?/' HTTP Request Denial of Service
CVE-2000-0984—doshardware25 oct 2000
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun HotJava Browser 3 - Arbitrary DOM Access
CVE-2000-0958—remotemultiple25 oct 2000
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named wind
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netscape Directory Server 4.12 - Directory Server Directory Traversal
CVE-2000-1075—remotewindows25 oct 2000
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iPlanet Certificate Management System 4.2 - Directory Traversal
CVE-2000-1075—remotewindows25 oct 2000
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Avirt Mail 4.0/4.2 - 'Mail From:' / 'Rcpt to:' Denial of Service
CVE-2000-0971—doswindows23 oct 2000
Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Allaire JRun 3 - Directory Disclosure
CVE-2000-1050—remotemultiple23 oct 2000
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Allaire JRun 2.3 - Arbitrary Code Execution
CVE-2000-1053—remotemultiple23 oct 2000
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scrip
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
David Bagley xlock 4.16 - User Supplied Format String (2)
CVE-2000-0763—localunix21 oct 2000
xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privile
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (2)
CVE-2000-0884—remotewindows21 oct 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP-UX 10.20/11.0 - crontab '/tmp' File
CVE-2000-0972—localhp-ux20 oct 2000
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target fil
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Intel InBusiness eMail Station 1.4.87 - Denial of Service
CVE-2000-0989—doshardware20 oct 2000
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Internet Directory 2.0.6 - oidldap
CVE-2000-0987—locallinux18 oct 2000
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line param
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hilgraeve HyperTerminal 6.0 - Telnet Buffer Overflow
CVE-2000-0991—doswindows18 oct 2000
Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (4)
CVE-2000-0884—remotewindows17 oct 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (1)
CVE-2000-0884—remotewindows17 oct 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (3)
CVE-2000-0884—remotewindows17 oct 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (5)
CVE-2000-0884—remotewindows17 oct 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
anaconda Foundation 1.4 < 1.9 - Directory Traversal
CVE-2000-0975—remotecgi13 oct 2000
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
cURL 6.1 < 7.4 - Remote Buffer Overflow (2)
CVE-2000-0973—remotelinux13 oct 2000
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft NetMeeting 3.0.1 4.4.3385 - Remote Desktop Sharing Denial of Service
CVE-2000-0983—doswindows13 oct 2000
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utili
28RIESGO
abrir ↗
← anteriorpágina 603 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.