Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
AnalogX Proxy 4.0 4 - Denial of Service
CVE-2000-0656—doswindows25 jul 2000
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netscape Communicator 4.x - JPEG-Comment Heap Overwrite
CVE-2000-0655—dosmultiple25 jul 2000
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary command
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 2.0./3.0/3.0.2.1 - Showcode
CVE-2000-0652—remotemultiple24 jul 2000
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default Invok
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'REST' Malformed File Write Denial of Service
CVE-2000-0645—doswindows21 jul 2000
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and wr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'STAT'/'LIST' Denial of Service
CVE-2000-0644—doswindows21 jul 2000
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Roxen WebServer 2.0.x - '%00' Request File/Directory Disclosure
CVE-2000-0671—remotemultiple21 jul 2000
Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory conten
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'MLST' Remote Denial of Service
CVE-2000-0647—doswindows21 jul 2000
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before loggin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tomcat 3.0/3.1 Snoop Servlet - Information Disclosure
CVE-2000-0760—remotemultiple20 jul 2000
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Tomcat 3.1 - Path Revealing
CVE-2000-0759—remotemultiple20 jul 2000
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not ex
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP JetDirect J3111A - Invalid FTP Command Denial of Service
CVE-2000-0636—doshardware19 jul 2000
HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Denial of Service
CVE-2000-0626—doswindows18 jul 2000
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
CVE-2000-0625—localwindows18 jul 2000
NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decryp
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Piped Command
CVE-2000-0626—remotecgi18 jul 2000
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (1)
CVE-2000-0567—remotewindows18 jul 2000
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (2)
CVE-2000-0567—remotewindows18 jul 2000
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Armada Design Master Index 1.0 - Directory Traversal
CVE-2000-0924—remotecgi18 jul 2000
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
CVE-2000-0684—localwindows18 jul 2000
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile an
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Source Fragment Disclosure
CVE-2000-0630—remotewindows17 jul 2000
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
CVE-2000-0666—remotelinux16 jul 2000
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, wh
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.5 - Denial of Service
CVE-2000-0473—doswindows15 jul 2000
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET reques
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 2.0/3.0/4.0/5.0/5.1 - Internal IP Address Disclosure
CVE-2000-0649—remotewindows13 jul 2000
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Infopulse GateKeeper 3.5 - Remote Buffer Overflow
CVE-2000-0675—remotewindows13 jul 2000
Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
alt-n WorldClient standard 2.1 - Directory Traversal
CVE-2000-0660—remotewindows12 jul 2000
The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CVSWeb Developer CVSWeb 1.80 - Insecure Perl 'open' Code Execution
CVE-2000-0670—localunix12 jul 2000
The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Netware 5.0 SP5/6.0 SP1 - SMDR.NLM Denial of Service
CVE-2000-0669—dosnovell11 jul 2000
Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Texas Imperial Software WFTPD 2.4.1 - RNTO Denial of Service
CVE-2000-0648—doswindows11 jul 2000
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command befor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.x - Directory Traversal
CVE-2000-0638—remotecgi11 jul 2000
bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PIX Firewall 2.7/3.x/4.x/5 - Forged TCP RST
CVE-2000-0613—remotehardware10 jul 2000
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to fo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DrPhibez and Nitro187 Guild FTPD 0.9.7 - File Existence Disclosure
CVE-2000-0640—remotewindows08 jul 2000
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format String
CVE-2000-0594—remotelinux05 jul 2000
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial
23RIESGO
abrir ↗
← anteriorpágina 608 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.