Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Microsoft SQL 2000/7.0 - Agent Jobs Privilege Escalation
CVE-2002-0721remotewindows15 ago 2002
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - HCP URI Handler Abuse
CVE-2002-0974remotewindows15 ago 2002
Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol
28RIESGO
abrir
Exploit-DBVexDay Proof
MyWebServer 1.0.2 - Long HTTP Request HTML Injection
CVE-2002-1453remotewindows14 ago 2002
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a lo
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.1 - Arbitrary Command Execution
CVE-2002-1951remotewindows14 ago 2002
Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request w
23RIESGO
abrir
Exploit-DBVexDay Proof
MyWebServer 1.0.2 - Search Request Remote Buffer Overflow
CVE-2002-1452remotewindows14 ago 2002
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a l
23RIESGO
abrir
Exploit-DBVexDay Proof
Leszek Krupinski L-Forum 2.4 - Search Script SQL Injection
CVE-2002-1457webappsphp14 ago 2002
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements v
23RIESGO
abrir
Exploit-DBVexDay Proof
RedHat Interchange 4.8.x - Arbitrary File Read
CVE-2002-0874remotelinux13 ago 2002
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to rea
23RIESGO
abrir
Exploit-DBVexDay Proof
W3C CERN HTTPd 3.0 Proxy - Cross-Site Scripting
CVE-2002-1445remoteunix12 ago 2002
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users v
23RIESGO
abrir
Exploit-DBVexDay Proof
ISDN4Linux 3.1 - IPPPD Device String SysLog Format String (2)
CVE-2002-0851locallinux10 ago 2002
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Midicart ASP - Remote Customer Information Retrieval
CVE-2002-1432webappsasp10 ago 2002
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensi
23RIESGO
abrir
Exploit-DBVexDay Proof
ISDN4Linux 3.1 - IPPPD Device String SysLog Format String (1)
CVE-2002-0851locallinux10 ago 2002
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows
23RIESGO
abrir
Exploit-DBVexDay Proof
BlueFace Falcon Web Server 2.0 - Error Message Cross-Site Scripting
CVE-2002-2318remotewindows09 ago 2002
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to i
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.0 - Encoded Backslash Directory Traversal
CVE-2002-0661remotewindows09 ago 2002
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to r
35RIESGO
abrir
Exploit-DBVexDay Proof
Orinoco OEM Residential Gateway - SNMP Community String Remote Configuration
CVE-2002-0812remotehardware09 ago 2002
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identif
23RIESGO
abrir
Exploit-DBVexDay Proof
Qualcomm Eudora 5/6 - File Attachment Spoofing (2)
CVE-2002-2351remotewindows08 ago 2002
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with
23RIESGO
abrir
Exploit-DBVexDay Proof
Qualcomm Eudora 5/6 - File Attachment Spoofing (1)
CVE-2002-2351remotewindows08 ago 2002
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (4)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (3)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Konqueror 2.2.2/3.0 / Weblogic Server 5/6/7 - Invalid X.509 Certificate Chain
CVE-2002-0828remotewindows06 ago 2002
20RIESGO
abrir
Exploit-DBVexDay Proof
qmailadmin 1.0.x - Local Buffer Overflow
CVE-2002-1414locallinux06 ago 2002
Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variab
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla 1.0/1.1 - FTP View Cross-Site Scripting
CVE-2002-2359remoteunix06 ago 2002
Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server 2000 - User Authentication Remote Buffer Overflow
CVE-2002-1123remotewindows06 ago 2002
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 al
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (8)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (7)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (5)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Konqueror 2.2.2/3.0 / Weblogic Server 5/6/7 - Invalid X.509 Certificate Chain
CVE-2002-0862remotewindows06 ago 2002
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (6)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (2)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Konqueror 2.2.2/3.0 / Weblogic Server 5/6/7 - Invalid X.509 Certificate Chain
CVE-2002-1183remotewindows06 ago 2002
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing r
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Window Message Subsystem Design Error (1)
CVE-2002-1230localwindows06 ago 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
anteriorpágina 748 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.