Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Juergen Weigert screen 3.9 - User Supplied Format String
CVE-2000-0901—localbsd05 sep 2000
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (1)
CVE-2000-0844—localunix04 sep 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (2)
CVE-2000-0844—localunix04 sep 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Immunix OS 6.2 - LC glibc format string
CVE-2000-0844—localimmunix04 sep 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AIX 4.2/4.3 - netstat -Z Statistic Clearing
CVE-2000-0873—localaix03 sep 2000
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network inte
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - '.photon' Directory Information Disclosure
CVE-2000-0904—remotemultiple01 sep 2000
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - Arbitrary File Access
CVE-2000-0903—remotemultiple01 sep 2000
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNOME esound 0.2.19 - Unix Domain Socket Race Condition
CVE-2000-0864—localunix31 ago 2000
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eEye Digital Security IRIS 1.0.1 / SpyNet CaptureNet 3.0.12 - Remote Buffer Overflow
CVE-2000-0734—remotewindows31 ago 2000
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGI Script Center Auction Weaver 1.0.2 - Remote Command Execution
CVE-2000-0690—remotecgi30 ago 2000
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ipswitch IMail 6.x - File Attachment
CVE-2000-0780—remotewindows30 ago 2000
The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (d
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GWScripts News Publisher 1.0 - 'author.file' Write
CVE-2000-0720—remotecgi29 ago 2000
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RobTex Viking Server 1.0.6 Build 355 - Remote Buffer Overflow
CVE-2000-0775—remotewindows28 ago 2000
Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Gert Doering mgetty 1.1.19/1.1.20/1.1.21/1.22.8 - Symbolic Link Traversal
CVE-2000-0691—localunix25 ago 2000
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
User-Mode Linux (Linux Kernel 2.4.17-8) - Memory Access Privilege Escalation
CVE-2002-2016—locallinux25 ago 2000
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
CVE-2000-0708—doswindows24 ago 2000
Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
CVE-2000-1002—doswindows24 ago 2000
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid pas
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (1)
CVE-2000-0688—remotecgi23 ago 2000
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (1)
CVE-2000-0689—remotecgi23 ago 2000
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (2)
CVE-2000-0689—remotecgi23 ago 2000
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (2)
CVE-2000-0688—remotecgi23 ago 2000
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP-UX 11.0 - net.init RC Script
CVE-2000-0702—localhp-ux22 ago 2000
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Darxite 0.4 - Login Buffer Overflow
CVE-2000-0846—remotelinux22 ago 2000
Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5 - Administrative Privileges
CVE-2000-0745—webappsphp21 ago 2000
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to ga
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UMN Gopherd 2.x - Halidate Function Buffer Overflow
CVE-2000-0743—remotelinux20 ago 2000
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Minicom 1.82/1.83 - Capture-file Group Ownership
CVE-2000-0698—locallinux19 ago 2000
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vqSoft vqServer 1.4.49 - Denial of Service
CVE-2000-0766—dosmultiple19 ago 2000
Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileg
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
netwin netauth 4.2 - Directory Traversal
CVE-2000-0782—remotecgi17 ago 2000
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
X-Chat 1.2/1.3/1.4/1.5 - Command Execution via URLs
CVE-2000-0787—remotelinux17 ago 2000
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell meta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (1)
CVE-2000-1037—remotemultiple15 ago 2000
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus in
23RIESGO
abrir ↗
← anteriorpágina 606 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.