Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
MySource 2.14 - 'header.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
NetFlow Analyzer 4 - Cross-Site Scripting
CVE-2005-3522webappsjsp18 Oct 2005
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Snort 2.4.0 < 2.4.3 - Back Orifice Pre-Preprocessor Remote (Metasploit)
CVE-2005-3252remotelinux18 Oct 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_cell_props.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting
CVE-2005-3520webappsphp18 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Lynx 2.8.6dev.13 - Remote Buffer Overflow (PoC)
CVE-2005-3120dosmultiple17 Oct 2005
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbit
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6 - Console Keymap Local Command Injection
CVE-2005-3257locallinux17 Oct 2005
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local
23RISK
open
Exploit-DBVexDay Proof
Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3285webappsasp17 Oct 2005
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows re
23RISK
open
Exploit-DBVexDay Proof
Opera 8.02 - Remote Denial of Service (2)
CVE-2005-4718doswindows16 Oct 2005
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RISK
open
Exploit-DBVexDay Proof
Opera 8.02 - Remote Denial of Service (1)
CVE-2005-4718dosmultiple16 Oct 2005
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RISK
open
Exploit-DBVexDay Proof
PunBB 1.2.x - 'search.php' SQL Injection
CVE-2005-3518webappsphp15 Oct 2005
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Complete PHP Counter - SQL Injection
CVE-2005-4674webappsphp14 Oct 2005
Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
Apache Tomcat 4.0.3 - Requests Containing MS-DOS Device Names Information Disclosure
CVE-2005-4703remotemultiple14 Oct 2005
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for
28RISK
open
Exploit-DBVexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
CVE-2001-1156doswindows14 Oct 2005
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1)
23RISK
open
Exploit-DBVexDay Proof
Complete PHP - Counter Cross-Site Scripting
CVE-2005-4675webappsphp14 Oct 2005
Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
CVE-2005-3294doswindows14 Oct 2005
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RISK
open
Exploit-DBVexDay Proof
YaPiG 0.95b - 'view.php?img_size' Cross-Site Scripting
CVE-2005-4799webappsphp13 Oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow rem
23RISK
open
Exploit-DBVexDay Proof
Accelerated Mortgage Manager - 'Password' SQL Injection
CVE-2005-3290webappsphp13 Oct 2005
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
WebGUI 6.x - Arbitrary Command Execution
CVE-2005-4694webappscgi12 Oct 2005
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - MSDTC TIP Denial of Service (MS05-051)
CVE-2005-1979doswindows11 Oct 2005
Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC servic
35RISK
open
Exploit-DBVexDay Proof
RARLAB WinRar 2.90/3.x - UUE/XXE Invalid Filename Error Message Format String
CVE-2005-3262doslinux11 Oct 2005
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via for
23RISK
open
Exploit-DBVexDay Proof
Accelerated E Solutions - SQL Injection
CVE-2005-4770webappsphp11 Oct 2005
SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.6.4-pl1 - Directory Traversal
CVE-2005-3299webappsphp10 Oct 2005
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to in
28RISK
open
Exploit-DBVexDay Proof
SGI IRIX 6.5.28 - 'runpriv' Design Error
CVE-2005-2925localirix10 Oct 2005
runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metachar
23RISK
open
Exploit-DBVexDay Proof
Up-IMAPProxy 1.2.3/1.2.4 - Multiple Unspecified Remote Format String Vulnerabilities
CVE-2005-2661doslinux10 Oct 2005
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows r
28RISK
open
Exploit-DBVexDay Proof
CA iTechnology iGateway - 'Debug Mode' Remote Buffer Overflow
CVE-2005-3190remotewindows10 Oct 2005
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RISK
open
Exploit-DBVexDay Proof
versatileBulletinBoard 1.00 RC2 - Board Takeover (SQL Injection)
CVE-2005-3259webappsphp10 Oct 2005
Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Xine-Lib 1.1 - 'Media Player Library' Remote Format String
CVE-2005-2967remotelinux10 Oct 2005
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allo
23RISK
open
previouspage 649 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.