Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Sun JavaMail 1.x - Multiple Information Disclosure Vulnerabilities
CVE-2005-1754webappsjava24 May 2005
JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a f
23RISK
open
Exploit-DBVexDay Proof
Blue Coat Reporter 7.0/7.1 - License HTML Injection
CVE-2005-1709remotewindows24 May 2005
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.
23RISK
open
Exploit-DBVexDay Proof
Gearbox Software Halo Game Server 1.06/1.07 - Infinite Loop Denial of Service
CVE-2005-1741doswindows24 May 2005
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malfo
23RISK
open
Exploit-DBVexDay Proof
Blue Coat Reporter 7.0/7.1 - Privilege Escalation
CVE-2005-1708remotewindows24 May 2005
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain adminis
23RISK
open
Exploit-DBVexDay Proof
GForge 3.x - Arbitrary Command Execution
CVE-2005-1752webappsphp24 May 2005
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell m
23RISK
open
Exploit-DBVexDay Proof
Warrior Kings: Battles 1.23 - Remote Denial of Service
CVE-2005-1703dosmultiple23 May 2005
Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partia
23RISK
open
Exploit-DBVexDay Proof
Warrior Kings 1.3 And Warrior Kings: Battles 1.23 - Remote Format String
CVE-2005-1702remotemultiple23 May 2005
Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote a
23RISK
open
Exploit-DBVexDay Proof
MWChat 6.8 - 'chat.php' SQL Injection
CVE-2005-3324webappsphp21 May 2005
SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
TCP TIMESTAMPS - Denial of Service
CVE-2005-0356dosmultiple21 May 2005
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled
45RISK
open
Exploit-DBVexDay Proof
WebAPP 0.9.9.2.1 - Remote Command Execution (2)
CVE-2005-1628webappscgi20 May 2005
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via
28RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.x - 'queryframe.php' Cross-Site Scripting
CVE-2005-3301webappsphp20 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.x - 'server_databases.php' Cross-Site Scripting
CVE-2005-3301webappsphp20 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
cPanel 9.1 - 'User' Cross-Site Scripting
CVE-2005-2021webappsphp20 May 2005
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
WebAPP 0.9.9.2.1 - Remote Command Execution (1)
CVE-2005-1628webappscgi20 May 2005
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via
28RISK
open
Exploit-DBVexDay Proof
Picasm 1.10/1.12 - Error Generation Remote Buffer Overflow
CVE-2005-1679remotefreebsd20 May 2005
Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary cod
23RISK
open
Exploit-DBVexDay Proof
D-Link DSL Router - Remote Authentication Bypass
CVE-2005-1827remotehardware19 May 2005
D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart
28RISK
open
Exploit-DBVexDay Proof
PHP Advanced Transfer Manager 1.21 - Arbitrary File Inclusion
CVE-2005-1681webappsphp19 May 2005
PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attac
23RISK
open
Exploit-DBVexDay Proof
BakBone NetVault 6.x/7.x - Remote Heap Buffer Overflow (1)
CVE-2005-1009remotewindows17 May 2005
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open
Exploit-DBVexDay Proof
BakBone NetVault 6.x/7.x - Remote Heap Buffer Overflow (1)
CVE-2005-1547remotewindows17 May 2005
Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.12-rc4 - 'ioctl_by_bdev' Local Denial of Service
CVE-2005-1589doslinux17 May 2005
The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier call
23RISK
open
Exploit-DBVexDay Proof
War Times - Remote Game Server Denial of Service
CVE-2005-1718doswindows17 May 2005
Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server cras
23RISK
open
Exploit-DBVexDay Proof
Gaim 1.2.1 - URL Handling Remote Stack Overflow
CVE-2005-1261doslinux17 May 2005
Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrar
28RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_themengraf.php?year' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
Mozilla Suite And Firefox - DOM Property Overrides Code Execution
CVE-2005-1532remotemultiple16 May 2005
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objec
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_sponsor.php?id' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_mitgraf.php?year' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_statistik.php?year' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal_viewsgraf.php?tag' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
NPDS 4.8/5.0 - 'comments.php?thold' SQL Injection
CVE-2005-1637webappsphp16 May 2005
Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1/3.0.2 - 'jgs_portal.php?anzahl_beitraege' SQL Injection
CVE-2005-1633webappsphp16 May 2005
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
previouspage 666 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.