Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.102exploits catalogados
35.951CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Savant Web Server 3.1 - Remote Buffer Overflow (2)
CVE-2002-1120remotewindows30 ago 2005
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RIESGO
abrir
Exploit-DBVexDay Proof
phpLDAPadmin 0.9.6/0.9.7 - 'welcome.php' Arbitrary File Inclusion
CVE-2005-2792webappsphp30 ago 2005
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitra
28RIESGO
abrir
Exploit-DBVexDay Proof
HP OpenView Network Node Manager 7.50 - Remote Command Execution
CVE-2005-2773CRITICALbajo ataqueremotemultiple30 ago 2005
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metach
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Version Cue 1.0/1.0.1 (OSX) - Local Privilege Escalation
CVE-2005-1842localosx30 ago 2005
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with V
23RIESGO
abrir
Exploit-DBVexDay Proof
Land Down Under 700/701/800/801 - 'events.php?c' SQL Injection
CVE-2005-2788webappsphp29 ago 2005
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWebNotes 2.0 - 'Api.php' Remote File Inclusion
CVE-2005-2775webappsphp29 ago 2005
php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to
23RIESGO
abrir
Exploit-DBVexDay Proof
Land Down Under 700/701/800/801 - 'list.php' Multiple SQL Injections
CVE-2005-2675webappsphp29 ago 2005
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Battlefield (BFCC < 1.22_A /BFVCC < 2.14_B / BF2CC) - Authentication Bypass / Password Stealer / Denial of Service
CVE-2004-1220remotewindows29 ago 2005
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion 4.0/5.0/6.0 - BBCode URL Tag Script Injection
CVE-2005-2783webappsphp29 ago 2005
Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Land Down Under 700/701/800/801 - 'index.php?c' SQL Injection
CVE-2005-2788webappsphp29 ago 2005
Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
bfcommand & control server 1.22/2.0/2.14 manager - Multiple Vulnerabilities
CVE-2005-2791remotemultiple29 ago 2005
BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cau
23RIESGO
abrir
Exploit-DBVexDay Proof
Autolinks 2.1 Pro - 'Al_initialize.php' Remote File Inclusion
CVE-2005-2782webappsphp29 ago 2005
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
SqWebMail 5.0.4 - HTML Email IMG Tag Script Injection
CVE-2005-2769webappsphp29 ago 2005
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to injec
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 2.x - 'error.php' Cross-Site Scripting
CVE-2005-2869webappsphp28 ago 2005
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Looking Glass 20040427 - Remote Command Execution
CVE-2005-2777webappsphp27 ago 2005
Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup
28RIESGO
abrir
Exploit-DBVexDay Proof
Astaro Security Linux 6.0 01 - HTTP CONNECT Unauthorized Access
CVE-2005-2729remotelinux25 ago 2005
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows re
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Plug-and-Play Service - Remote Universal (Spanish) (MS05-039)
CVE-2005-1983remotewindows25 ago 2005
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RIESGO
abrir
Exploit-DBVexDay Proof
QNX RTOS 6.1/6.3 - InputTrap Local Arbitrary File Disclosure
CVE-2005-2725locallinux24 ago 2005
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the
23RIESGO
abrir
Exploit-DBVexDay Proof
LeapFTP Client 2.7.3/2.7.4 - '.LSQ' File Remote Buffer Overflow (PoC)
CVE-2005-2767doswindows24 ago 2005
Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.ls
23RIESGO
abrir
Exploit-DBVexDay Proof
Foojan PHPWeblog - Html Injection
CVE-2005-2721webappsphp24 ago 2005
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Ventrilo 2.3.0 (All Platforms) - Remote Denial of Service
CVE-2005-2719dosmultiple23 ago 2005
Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packe
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPKit 1.6.1 - 'member.php' SQL Injection
CVE-2005-2683webappsphp22 ago 2005
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercora IMRadio 4.0.0.0 - Local Password Disclosure
CVE-2005-2866localwindows22 ago 2005
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which al
23RIESGO
abrir
Exploit-DBVexDay Proof
PostNuke 0.76 RC4b Comments Module - 'moderate' Cross-Site Scripting
CVE-2005-2689webappsphp22 ago 2005
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.00 RC4 - 'search.php' SQL Injection
CVE-2005-2697webappsphp22 ago 2005
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
PostNuke 0.75/0.76 DL - 'viewdownload.php' SQL Injection
CVE-2005-2690webappsphp22 ago 2005
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
PostNuke 0.76 RC4b - 'user.php?htmltext' Cross-Site Scripting
CVE-2005-2689webappsphp22 ago 2005
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.2.3 for Mac OS - Denial of Service
CVE-2005-3077dososx22 ago 2005
Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page
28RIESGO
abrir
Exploit-DBVexDay Proof
ZipTorrent 1.3.7.3 - Local Proxy Password Disclosure
CVE-2005-2868localwindows22 ago 2005
ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain se
23RIESGO
abrir
Exploit-DBVexDay Proof
Elm < 2.5.8 - Expires Header Remote Buffer Overflow
CVE-2005-2665remotelinux22 ago 2005
Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attacker
28RIESGO
abrir
anteriorpágina 654 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.