Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Azerbaijan Development Group AzDGDatingPlatinum 1.1.0 - 'view.php?id' SQL Injection
CVE-2005-1082webappsphp09 Apr 2005
Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
RadScripts RadBids Gold 2.0 - 'index.php?mode' SQL Injection
CVE-2005-1074webappsphp09 Apr 2005
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - BlueTooth Signed Buffer Index Privilege Escalation (1)
CVE-2005-0750locallinux08 Apr 2005
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RISK
open
Exploit-DBVexDay Proof
The Includer CGI 1.0 - Remote Command Execution (3)
CVE-2005-0689webappscgi08 Apr 2005
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISK
open
Exploit-DBVexDay Proof
The Includer CGI 1.0 - Remote Command Execution (2)
CVE-2005-0689webappscgi08 Apr 2005
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RISK
open
Exploit-DBVexDay Proof
AN HTTPD - 'CMDIS.dll' Remote Buffer Overflow (PoC)
CVE-2005-1086doswindows08 Apr 2005
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
PostNuke Phoenix 0.760 RC3 - 'OP' Cross-Site Scripting
CVE-2005-1049webappsphp08 Apr 2005
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
PostNuke Phoenix 0.760 RC3 - 'Module' Cross-Site Scripting
CVE-2005-1049webappsphp08 Apr 2005
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
AN HTTPD 1.42 - Arbitrary Log Content Injection
CVE-2005-1087remotewindows08 Apr 2005
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide
23RISK
open
Exploit-DBVexDay Proof
P2P Share Spy 2.2 - Local Password Disclosure
CVE-2005-1097localwindows07 Apr 2005
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows l
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 6.x < 7.6 Top module - SQL Injection
CVE-2005-0999webappsphp07 Apr 2005
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Linksys WET11 - Password Update Remote Authentication Bypass
CVE-2005-1059remotehardware07 Apr 2005
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data
23RISK
open
Exploit-DBVexDay Proof
SGI IRIX 6.5.22 - GR_OSView Information Disclosure
CVE-2005-0464localirix07 Apr 2005
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files w
23RISK
open
Exploit-DBVexDay Proof
SGI IRIX 6.5.22 - GR_OSView Local Arbitrary File Overwrite
CVE-2005-0465localirix07 Apr 2005
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary fil
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple SQL Injections
CVE-2005-0997webappsphp07 Apr 2005
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Active Auction House - 'start.asp?ReturnURL' Cross-Site Scripting
CVE-2005-1030webappsasp06 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
CubeCart 2.0.x - 'view_cart.php?add' Full Path Disclosure
CVE-2005-1033webappsphp06 Apr 2005
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open
Exploit-DBVexDay Proof
IBM Lotus Domino Server 6.5.1 Web Service - Remote Denial of Service
CVE-2005-0986dosunix06 Apr 2005
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Active Auction House - 'WatchThisItem.asp' Cross-Site Scripting
CVE-2005-1030webappsasp06 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Active Auction House - 'account.asp?ReturnURL' Cross-Site Scripting
CVE-2005-1030webappsasp06 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
phpBB 2.0.13 Linkz Pro Module - SQL Injection
CVE-2005-1026webappsphp06 Apr 2005
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
phpBB 2.0.13 DLMan Pro Module - SQL Injection
CVE-2005-1026webappsphp06 Apr 2005
Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
Active Auction House - 'ItemInfo.asp' SQL Injection
CVE-2005-1029webappsasp06 Apr 2005
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
CubeCart 2.0.x - 'view_product.php?product' Full Path Disclosure
CVE-2005-1033webappsphp06 Apr 2005
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open
Exploit-DBVexDay Proof
FTP Now 2.6.14 - Local Password Disclosure
CVE-2005-1094localwindows06 Apr 2005
FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local use
23RISK
open
Exploit-DBVexDay Proof
Ocean12 Membership Manager Pro - Cross-Site Scripting
CVE-2005-1095webappsphp06 Apr 2005
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to i
23RISK
open
Exploit-DBVexDay Proof
CubeCart 2.0.x - 'tellafriend.php?product' Full Path Disclosure
CVE-2005-1033webappsphp06 Apr 2005
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.6 Web_Links Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-1000webappsphp06 Apr 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
Active Auction House - 'default.asp' Multiple SQL Injections
CVE-2005-1029webappsasp06 Apr 2005
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
CubeCart 2.0.x - 'index.php' Multiple Full Path Disclosures
CVE-2005-1033webappsphp06 Apr 2005
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.ph
23RISK
open
previouspage 674 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.