Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
TWiki TWikiUsers - INCLUDE Function Arbitrary Command Execution
CVE-2005-2877webappsphp28 Sep 2005
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISK
open
Exploit-DBVexDay Proof
LucidCMS 2.0 - 'index.php' Cross-Site Scripting
CVE-2005-3127webappsphp27 Sep 2005
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Novell Groupwise Client 6.5.3 - Local Integer Overflow
CVE-2005-2804doswindows27 Sep 2005
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Barracuda Spam Firewall < 3.1.18 - Command Execution (Metasploit)
CVE-2005-2848webappscgi27 Sep 2005
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote
23RISK
open
Exploit-DBVexDay Proof
Barracuda Spam Firewall < 3.1.18 - Command Execution (Metasploit)
CVE-2005-2847webappscgi27 Sep 2005
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary comman
50RISK
open
Exploit-DBVexDay Proof
MultiTheftAuto 0.5 patch 1 - Server Crash / MOTD Deletion
CVE-2005-3064doswindows26 Sep 2005
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows
23RISK
open
Exploit-DBVexDay Proof
GNU Mailutils imap4d 0.6 (FreeBSD) - 'Search' Remote Format String
CVE-2005-2878remotebsd26 Sep 2005
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to e
28RISK
open
Exploit-DBVexDay Proof
RealPlayer/Helix Player (Linux) - Remote Format String
CVE-2005-2710remotelinux26 Sep 2005
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via
28RISK
open
Exploit-DBVexDay Proof
CMS Made Simple 0.10 - 'index.php' Cross-Site Scripting
CVE-2005-3083webappsphp26 Sep 2005
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
Qpopper 4.0.8 (FreeBSD) - Local Privilege Escalation
CVE-2005-3098localbsd24 Sep 2005
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace fi
23RISK
open
Exploit-DBVexDay Proof
Qpopper 4.0.8 (Linux) - 'poppassd' Local Privilege Escalation
CVE-2005-3098locallinux24 Sep 2005
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace fi
23RISK
open
Exploit-DBVexDay Proof
MailGust 1.9 - Board Takeover (SQL Injection)
CVE-2005-3063webappsphp24 Sep 2005
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email fiel
23RISK
open
Exploit-DBVexDay Proof
WzdFTPD 0.5.4 - Remote Command Execution
CVE-2005-3081remotelinux24 Sep 2005
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE comma
45RISK
open
Exploit-DBVexDay Proof
Nokia Symbian 60 - 'BlueTooth Nickname' Remote Restart (2)
CVE-2005-0681doshardware23 Sep 2005
Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.
23RISK
open
Exploit-DBVexDay Proof
phpMyFAQ 1.5.1 - 'User-Agent' Remote Shell Injection
CVE-2005-3048webappsphp23 Sep 2005
Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or incl
23RISK
open
Exploit-DBVexDay Proof
Mozilla Browsers - 0xAD (HOST:) Remote Heap Buffer Overrun (2)
CVE-2005-2871remotewindows22 Sep 2005
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.
28RISK
open
Exploit-DBVexDay Proof
My Little Forum 1.5 - 'SearchString' SQL Injection
CVE-2005-3045webappsphp22 Sep 2005
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01a (Pegasus) - IMAP Buffer Overflow
CVE-2007-1373remotewindows20 Sep 2005
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISK
open
Exploit-DBVexDay Proof
Hesk 0.92/0.93 - Session ID Authentication Bypass
CVE-2005-3005webappsphp20 Sep 2005
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modi
23RISK
open
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01a (Pegasus) - IMAP Buffer Overflow
CVE-2006-5961remotewindows20 Sep 2005
Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally
23RISK
open
Exploit-DBVexDay Proof
Mozilla Browser/Firefox - Arbitrary Command Execution
CVE-2005-2968remotelinux20 Sep 2005
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that i
28RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertitle.php?usertitleid' SQL Injection
CVE-2005-3019webappsphp19 Sep 2005
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3020webappsphp19 Sep 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php?email' Cross-Site Scripting
CVE-2005-3020webappsphp19 Sep 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/modlog.php?orderby' Cross-Site Scripting
CVE-2005-3020webappsphp19 Sep 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/language.php?goto' Cross-Site Scripting
CVE-2005-3020webappsphp19 Sep 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertools.php?ids' SQL Injection
CVE-2005-3019webappsphp19 Sep 2005
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/css.php?group' Cross-Site Scripting
CVE-2005-3020webappsphp19 Sep 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
MCCS (Multi-Computer Control Systems) Command - Denial of Service
CVE-2005-3002doswindows19 Sep 2005
Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet
23RISK
open
Exploit-DBVexDay Proof
EPay Pro 2.0 - 'index.php' Directory Traversal
CVE-2005-3026webappsphp19 Sep 2005
Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read ar
23RISK
open
previouspage 651 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.