Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Comersus Backoffice 4.x/5.0/6.0 - 'comersus_Backoffice_supportError.asp?error' Cross-Site Scripting
CVE-2005-3397webappsasp31 Oct 2005
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
phpFaber CMS 1.3.36 - 'Htmlarea.php' Cross-Site Scripting
CVE-2006-5626webappsphp30 Oct 2005
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (C
23RISK
open
Exploit-DBVexDay Proof
MG2 0.5.1 - Authentication Bypass
CVE-2005-3432webappsphp29 Oct 2005
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list
23RISK
open
Exploit-DBVexDay Proof
ASP Fast Forum - 'error.asp' Cross-Site Scripting
CVE-2005-3422webappsasp27 Oct 2005
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Hasbani-WindWeb/2.0 - GET Remote Denial of Service
CVE-2005-3475doshardware27 Oct 2005
Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted G
23RISK
open
Exploit-DBVexDay Proof
ATutor 1.x - 'print.php?section' Remote File Inclusion
CVE-2005-3404webappsphp27 Oct 2005
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrar
28RISK
open
Exploit-DBVexDay Proof
ATutor 1.x - 'forum.inc.php' Arbitrary Command Execution
CVE-2005-3405webappsphp27 Oct 2005
ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.
23RISK
open
Exploit-DBVexDay Proof
ATutor 1.x - 'body_header.inc.php?section' Local File Inclusion
CVE-2005-3404webappsphp27 Oct 2005
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrar
28RISK
open
Exploit-DBVexDay Proof
Novell ZENworks Patch Management 6.0.52 - '/computers/default.asp?Direction' SQL Injection
CVE-2005-3315webappsasp27 Oct 2005
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Novell ZENworks Patch Management 6.0.52 - '/reports/default.asp' Multiple SQL Injections
CVE-2005-3315webappsasp27 Oct 2005
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers t
23RISK
open
Exploit-DBVexDay Proof
saPHP Lesson - 'add.php?forumid' SQL Injection
CVE-2005-3363webappsphp26 Oct 2005
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)
CVE-2005-1294locallinux26 Oct 2005
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a
23RISK
open
Exploit-DBVexDay Proof
TClanPortal 1.1.3 - 'id' SQL Injection
CVE-2005-4656webappsphp26 Oct 2005
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
IPBProArcade 2.5.2 - 'GameID' SQL Injection
CVE-2005-4702webappsphp26 Oct 2005
SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.0 - 'usercp.php' SQL Injection
CVE-2005-3326webappsphp26 Oct 2005
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
Flyspray 0.9 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3334webappsphp26 Oct 2005
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke Search Enhanced Module 1.1/2.0 - HTML Injection
CVE-2005-3368webappsphp26 Oct 2005
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Snoopy 0.9x/1.0/1.2 - Arbitrary Command Execution
CVE-2005-3330remotewindows26 Oct 2005
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4)
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)
CVE-2005-0750locallinux26 Oct 2005
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RISK
open
Exploit-DBVexDay Proof
GCards 1.43 - 'news.php' SQL Injection
CVE-2005-3408webappsphp26 Oct 2005
SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Woltlab 1.1/2.x - 'Info-DB Info_db.php' Multiple SQL Injections
CVE-2005-3369webappsphp26 Oct 2005
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allo
23RISK
open
Exploit-DBVexDay Proof
RSA ACE Agent 5.x - Image Cross-Site Scripting
CVE-2005-3329webappscgi26 Oct 2005
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Belchior Foundry VCard 2.9 - Remote File Inclusion
CVE-2005-3332webappsphp26 Oct 2005
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Parsing Remote Buffer Overflow
CVE-2005-3252remotelinux25 Oct 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open
Exploit-DBVexDay Proof
Basic Analysis and Security Engine (BASE) 1.2 - 'Base_qry_main.php' SQL Injection
CVE-2005-3325webappsphp25 Oct 2005
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6
23RISK
open
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Sections Module - 'artid' SQL Injection
CVE-2005-3305webappsphp24 Oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Plug-and-Play - 'Umpnpmgr.dll' Denial of Service (MS05-047) (2)
CVE-2005-2120doswindows24 Oct 2005
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RISK
open
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Download Module - 'dl_id' SQL Injection
CVE-2005-3305webappsphp24 Oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
SiteTurn Domain Manager Pro - Admin Panel Cross-Site Scripting
CVE-2005-3320webappsphp24 Oct 2005
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
CVE-2005-3305webappsphp24 Oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
previouspage 647 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.