Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Webhints 1.03 - Remote Command Execution (Perl) (3)
CVE-2005-1950webappscgi11 Jun 2005
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RISK
open
Exploit-DBVexDay Proof
Webhints 1.03 - Remote Command Execution (Perl) (1)
CVE-2005-1950webappscgi11 Jun 2005
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RISK
open
Exploit-DBVexDay Proof
Webhints 1.03 - Remote Command Execution (C) (2)
CVE-2005-1950webappscgi11 Jun 2005
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RISK
open
Exploit-DBVexDay Proof
Tcpdump - bgp_update_print Remote Denial of Service
CVE-2005-1267dosmultiple09 Jun 2005
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function
28RISK
open
Exploit-DBVexDay Proof
Invision Power Services Invision Gallery 1.0.1/1.3 - SQL Injection
CVE-2005-1948webappsphp09 Jun 2005
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Loki Download Manager 2.0 - 'default.asp' SQL Injection
CVE-2005-1943webappsasp08 Jun 2005
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Loki Download Manager 2.0 - 'Catinfo.asp' SQL Injection
CVE-2005-1943webappsasp08 Jun 2005
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
IPSwitch IMAP Server - LOGON Remote Stack Overflow
CVE-2005-1255remotewindows07 Jun 2005
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), a
35RISK
open
Exploit-DBVexDay Proof
GoodTech SMTP Server 5.14 - Denial of Service
CVE-2005-1931doswindows07 Jun 2005
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command
23RISK
open
Exploit-DBVexDay Proof
WinZip 8.1 - Command Line Local Buffer Overflow
CVE-2004-1465localwindows07 Jun 2005
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors,
23RISK
open
Exploit-DBVexDay Proof
FlatNuke 2.5.x - 'help.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-1895webappsphp07 Jun 2005
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTM
23RISK
open
Exploit-DBVexDay Proof
FlatNuke 2.5.x - 'referer.php' Crafted Referer Arbitrary PHP Code Execution
CVE-2005-1894webappsphp07 Jun 2005
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing t
23RISK
open
Exploit-DBVexDay Proof
FlatNuke 2.5.x - 'index.php?where' Full Path Disclosure
CVE-2005-1893webappsphp07 Jun 2005
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which
23RISK
open
Exploit-DBVexDay Proof
Kaspersky AntiVirus - 'klif.sys' Local Privilege Escalation
CVE-2005-1905localwindows07 Jun 2005
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gai
23RISK
open
Exploit-DBVexDay Proof
FUSE 2.2/2.3 - Local Information Disclosure
CVE-2005-1858locallinux06 Jun 2005
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a s
23RISK
open
Exploit-DBVexDay Proof
Rakkarsoft RakNet 2.33 - Remote Denial of Service
CVE-2005-1899dosmultiple06 Jun 2005
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products i
23RISK
open
Exploit-DBVexDay Proof
YaPiG 0.9x - 'view.php' Cross-Site Scripting
CVE-2005-1886webappsphp06 Jun 2005
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject a
23RISK
open
Exploit-DBVexDay Proof
Early Impact ProductCart 2.6/2.7 - 'OptionFieldsEdit.asp?idccr' SQL Injection
CVE-2005-1967webappsasp06 Jun 2005
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
YaPiG 0.9x - Local/Remote File Inclusion
CVE-2005-1881webappsphp06 Jun 2005
upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which
23RISK
open
Exploit-DBVexDay Proof
Early Impact ProductCart 2.6/2.7 - 'editCategories.asp?lid' SQL Injection
CVE-2005-1967webappsasp06 Jun 2005
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
Portail PHP < 1.3 - SQL Injection
CVE-2005-1701webappsphp06 Jun 2005
SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id param
23RISK
open
Exploit-DBVexDay Proof
Early Impact ProductCart 2.6/2.7 - 'modCustomCardPaymentOpt.asp?idc' SQL Injection
CVE-2005-1967webappsasp06 Jun 2005
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
Early Impact ProductCart 2.6/2.7 - 'viewPrd.asp?idcategory' SQL Injection
CVE-2005-1967webappsasp06 Jun 2005
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
YaPiG 0.9x - 'upload.php' Directory Traversal
CVE-2005-1884webappsphp06 Jun 2005
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u a
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.750 - 'readpmsg.php' SQL Injection
CVE-2005-1777webappsphp05 Jun 2005
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Popper Webmail 1.41 - 'ChildWindow.Inc.php' Remote File Inclusion
CVE-2005-1870webappsphp03 Jun 2005
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Crob FTP Server 3.6.1 - Remote Stack Overflow
CVE-2005-1873remotewindows03 Jun 2005
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
FutureSoft TFTP Server 2000 - Remote Denial of Service
CVE-2005-1812doswindows02 Jun 2005
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to exe
50RISK
open
Exploit-DBVexDay Proof
e-Post SPA-PRO 4.01 - 'imap' Remote Buffer Overflow
CVE-2005-1903remotewindows02 Jun 2005
Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
DUware DUclassmate 1.x - 'edit.asp?iPro' SQL Injection
CVE-2005-2049webappsasp01 Jun 2005
Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL command
23RISK
open
previouspage 663 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.