Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Mtp-Target Server 1.2.2 - Memory Corruption
CVE-2005-1402dosmultiple02 May 2005
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and poss
23RISK
open
Exploit-DBVexDay Proof
CodetoSell ViArt Shop Enterprise 2.1.6 - 'page.php?page' Cross-Site Scripting
CVE-2005-1440webappsphp02 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
CodetoSell ViArt Shop Enterprise 2.1.6 - 'reviews.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-1440webappsphp02 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
CodetoSell ViArt Shop Enterprise 2.1.6 - 'product_details.php?category_id' Cross-Site Scripting
CVE-2005-1440webappsphp02 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Maxwebportal 1.3 - 'pic_popular.asp' SQL Injection
CVE-2005-1417webappsasp02 May 2005
Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
CodetoSell ViArt Shop Enterprise 2.1.6 - 'products.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-1440webappsphp02 May 2005
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
GlobalScape Secure FTP Server 3.0 - Remote Buffer Overflow
CVE-2005-1415remotewindows01 May 2005
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
Keyvan1 ImageGallery - Database Disclosure
CVE-2005-1645webappsasp01 May 2005
Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which a
23RISK
open
Exploit-DBVexDay Proof
ARPUS/Ce - Local Overflow (setuid)
CVE-2005-1396locallinux01 May 2005
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlin
23RISK
open
Exploit-DBVexDay Proof
ARPUS/Ce - Local File Overwrite (setuid)
CVE-2005-1396locallinux01 May 2005
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlin
23RISK
open
Exploit-DBVexDay Proof
JGS-Portal 3.0.1 - 'ID' SQL Injection
CVE-2005-1479webappsphp30 Apr 2005
SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
Solaris 10.x - ESRI Arcgis Format String Privilege Escalation
CVE-2005-1394localsolaris30 Apr 2005
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format
23RISK
open
Exploit-DBVexDay Proof
Golden FTP Server Pro 2.52 - Remote Buffer Overflow (3)
CVE-2005-0634remotewindows29 Apr 2005
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
28RISK
open
Exploit-DBVexDay Proof
Golden FTP Server Pro 2.52 - Remote Buffer Overflow (2)
CVE-2005-0634remotewindows29 Apr 2005
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
28RISK
open
Exploit-DBVexDay Proof
Snmppd - SNMP Proxy Daemon Remote Format String
CVE-2005-1246remotelinux29 Apr 2005
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote at
23RISK
open
Exploit-DBVexDay Proof
Golden FTP Server Pro 2.52 - Remote Buffer Overflow (1)
CVE-2005-0634remotewindows29 Apr 2005
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
28RISK
open
Exploit-DBVexDay Proof
BulletProof FTP Server 2.4.0.31 - Local Privilege Escalation
CVE-2005-1371localwindows29 Apr 2005
BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through th
23RISK
open
Exploit-DBVexDay Proof
Just William's Amazon Webstore - 'CurrentIsExpanded' Cross-Site Scripting
CVE-2005-1403webappsphp28 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
GoText 1.01 - Local User Informations Disclosure
CVE-2005-1424localwindows28 Apr 2005
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoTex
23RISK
open
Exploit-DBVexDay Proof
NotJustBrowsing 1.0.3 - Local Password Disclosure
CVE-2005-1418localwindows28 Apr 2005
NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which
23RISK
open
Exploit-DBVexDay Proof
Oracle Application Server 9.0 - HTTP Service Mod_Access Restriction Bypass
CVE-2005-1383remotemultiple28 Apr 2005
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attacke
35RISK
open
Exploit-DBVexDay Proof
HP OpenView Radia Management Portal 1.0/2.0 - Remote Command Execution
CVE-2005-1370remotewindows28 Apr 2005
Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows re
23RISK
open
Exploit-DBVexDay Proof
FilePocket 1.2 - Local Proxy Password Disclosure
CVE-2005-1414localwindows28 Apr 2005
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, w
23RISK
open
Exploit-DBVexDay Proof
Oracle Application Server 9i Webcache - Arbitrary File Corruption
CVE-2005-1382remotemultiple28 Apr 2005
The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in
23RISK
open
Exploit-DBVexDay Proof
Just William's Amazon Webstore - 'searchFor' Cross-Site Scripting
CVE-2005-1403webappsphp28 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
ICUII 7.0 - Local Password Disclosure
CVE-2005-1411localwindows28 Apr 2005
Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain
23RISK
open
Exploit-DBVexDay Proof
phpBB Notes Module - SQL Injection
CVE-2005-1378webappsphp28 Apr 2005
SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Oracle Application Server 9i - Webcache Cache_dump_file Cross-Site Scripting
CVE-2005-1381remotemultiple28 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web
28RISK
open
Exploit-DBVexDay Proof
Just William's Amazon Webstore - 'CurrentNumber' Cross-Site Scripting
CVE-2005-1403webappsphp28 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
phpCOIN 1.2 - 'login.php?PHPcoinsessid' SQL Injection
CVE-2005-1384webappsphp28 Apr 2005
Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
previouspage 669 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.