Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Symantec Multiple Firewall - DNS Response Denial of Service
CVE-2004-0445doswindows16 mai 2004
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - http-equiv Meta Tag Denial of Service
CVE-2004-0479doswindows14 mai 2004
Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Outlook 2003 - Mail Client E-mail Address Verification
CVE-2004-0501remotewindows11 mai 2004
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a re
28RISCO
abrir
Exploit-DBVexDay Proof
NetBSD/FreeBSD Port Systrace 1.x - Exit Routine Access Validation Privilege Escalation
CVE-2004-2012localbsd11 mai 2004
The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 4/5/6 - Embedded Image URI Obfuscation
CVE-2004-0526remotewindows10 mai 2004
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Outlook 2003 - Predictable File Location
CVE-2004-0502remotewindows10 mai 2004
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img
28RISCO
abrir
Exploit-DBVexDay Proof
National Science Foundation Squid Proxy 2.3 - Internet Access Control Bypass
CVE-2004-2480remotelinux10 mai 2004
Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via
23RISCO
abrir
Exploit-DBVexDay Proof
MailEnable Mail Server HTTPMail 1.x - Remote Heap Overflow
CVE-2004-2727doswindows09 mai 2004
Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a deni
23RISCO
abrir
Exploit-DBVexDay Proof
Qualcomm Eudora 6.x - Embedded Hyperlink URI Obfuscation
CVE-2004-2649remotewindows08 mai 2004
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of char
23RISCO
abrir
Exploit-DBVexDay Proof
Adam Webb NukeJokes 1.7/2.0 Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2007webappsphp08 mai 2004
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
Adam Webb NukeJokes 1.7/2.0 Module - 'modules.php?jokeid' SQL Injection
CVE-2004-2008webappsphp08 mai 2004
SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
Qualcomm Eudora 5.2.1/6.x - Embedded Hyperlink Buffer Overrun
CVE-2004-2005doslinux07 mai 2004
Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-m
23RISCO
abrir
Exploit-DBVexDay Proof
DeleGate 7.8.x/8.x - SSLway Filter Remote Stack Buffer Overflow (PoC)
CVE-2004-2003doslinux06 mai 2004
Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Exim Sender 3.35 - Verification Remote Stack Buffer Overrun
CVE-2004-0399remotelinux06 mai 2004
Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows rem
28RISCO
abrir
Exploit-DBVexDay Proof
MyWeb HTTP Server 3.3 - GET Buffer Overflow
CVE-2004-2614remotewindows06 mai 2004
Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - '/images.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364webappsphp05 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
XChat 1.8.0/2.0.8 socks5 - Remote Buffer Overflow
CVE-2004-0409remotelinux05 mai 2004
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows re
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2363webappsphp05 mai 2004
Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allow
23RISCO
abrir
Exploit-DBVexDay Proof
E-Zone Media FuzeTalk 2.0 - 'AddUser.cfm' Administrator Command Execution
CVE-2004-1995webappscfm05 mai 2004
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via
23RISCO
abrir
Exploit-DBVexDay Proof
Simple Machines Forum (SMF) 1.0 - Size Tag HTML Injection
CVE-2004-1996webappsphp05 mai 2004
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - '/page.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364webappsphp05 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
SurgeLDAP 1.0 - Web Administration Authentication Bypass
CVE-2004-2254webappscgi05 mai 2004
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - '/user.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364webappsphp05 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - '/news.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364webappsphp05 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.x - '/forums.php' Cross-Site Request Forgery / Arbitrary Command Execution
CVE-2004-2364webappsphp05 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DB
PHPX < 3.26 - Multiple Vulnerabilities
CVE-2004-2364webappsphp04 mai 2004
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
Titan FTP Server 3.0 - 'LIST' Denial of Service
CVE-2004-0437doswindows04 mai 2004
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users
38RISCO
abrir
Exploit-DBVexDay Proof
APSIS Pound 1.5 - Remote Format String
CVE-2004-2026remotelinux03 mai 2004
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
PaX 2.6 Kernel Patch - Denial of Service
CVE-2004-1983doslinux03 mai 2004
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomi
23RISCO
abrir
Exploit-DBVexDay Proof
Business Objects Crystal Reports 9/10 Web Form Viewer - Directory Traversal
CVE-2004-0204remotewindows03 mai 2004
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterpri
45RISCO
abrir
anteriorpágina 703 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.