Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
ProjectBB 0.4.5.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0650webappsphp02 Mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
AWStats 5.7 < 6.2 - Multiple Remote s
CVE-2005-0438webappscgi02 Mar 2005
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter
23RISK
open
Exploit-DBVexDay Proof
PHPNews 1.2.3/1.2.4 - 'auth.php' Remote File Inclusion
CVE-2005-0632webappsphp01 Mar 2005
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
PHPCOIN 1.2 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0670webappsphp01 Mar 2005
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
PHPCOIN 1.2 - 'mod.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0670webappsphp01 Mar 2005
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
427BB 2.x - Multiple Remote HTML Injection Vulnerabilities
CVE-2005-0629webappsphp01 Mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
Scrapland 1.0 - Server Termination Denial of Service
CVE-2005-0621doswindows28 Feb 2005
Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an err
23RISK
open
Exploit-DBVexDay Proof
Einstein 1.01 - Local Password Disclosure (ASM)
CVE-2005-0619localwindows28 Feb 2005
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows l
23RISK
open
Exploit-DBVexDay Proof
BadBlue 2.5 - Easy File Sharing Remote Buffer Overflow
CVE-2005-0595remotewindows27 Feb 2005
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand
50RISK
open
Exploit-DBVexDay Proof
eXeem 0.21 - Local Password Disclosure (ASM)
CVE-2005-0518localwindows26 Feb 2005
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RISK
open
Exploit-DBVexDay Proof
KNet Web Server 1.04c - Buffer Overflow (Denial of Service) (PoC)
CVE-2005-0575doswindows25 Feb 2005
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RISK
open
Exploit-DBVexDay Proof
WU-FTPD 2.6.2 - File Globbing Denial of Service
CVE-2005-0256doslinux25 Feb 2005
The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
CubeCart 2.0.x - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0606webappsphp25 Feb 2005
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP f
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.6 - 'select_server.lib.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0543webappsphp24 Feb 2005
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.6 - 'display_tbl_links.lib.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0543webappsphp24 Feb 2005
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RISK
open
Exploit-DBVexDay Proof
Avaya IP Office Phone Manager - Local Password Disclosure
CVE-2005-0506localwindows24 Feb 2005
The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a
23RISK
open
Exploit-DBVexDay Proof
PunBB 3.0/3.1 - Multiple Remote Input Validation Vulnerabilities
CVE-2005-0569webappsphp24 Feb 2005
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (
23RISK
open
Exploit-DBVexDay Proof
Soldier of Fortune 2 1.03 - 'cl_guid' Server Crash
CVE-2005-0568doswindows24 Feb 2005
Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.6 - 'theme_right.css.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0543webappsphp24 Feb 2005
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 2.6 - 'theme_left.css.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0543webappsphp24 Feb 2005
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RISK
open
Exploit-DBVexDay Proof
webconnect 6.4.4 < 6.5 - Directory Traversal / Denial of Service
CVE-2004-0465dosmultiple24 Feb 2005
Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows rem
28RISK
open
Exploit-DBVexDay Proof
Chat Anywhere 2.72a - Local Password Disclosure
CVE-2005-0522localwindows23 Feb 2005
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which a
23RISK
open
Exploit-DBVexDay Proof
Winace UnAce 1.x - ACE Archive Directory Traversal
CVE-2005-0161remotelinux23 Feb 2005
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archi
23RISK
open
Exploit-DBVexDay Proof
eXeem 0.21 - Local Password Disclosure
CVE-2005-0518localwindows22 Feb 2005
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RISK
open
Exploit-DBVexDay Proof
PeerFTP 5 - Local Password Disclosure
CVE-2005-0517localwindows22 Feb 2005
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0.6 - PHP Code Injection
CVE-2005-0511webappsphp22 Feb 2005
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers
50RISK
open
Exploit-DBVexDay Proof
SendLink 1.5 - Local Password Disclosure
CVE-2005-0521localwindows22 Feb 2005
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows
23RISK
open
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 1.x/2.0.3 - SML Code Script Injection
CVE-2005-0477webappsphp21 Feb 2005
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
SHOUTcast 1.9.4 (Windows) - File Request Format String Remote Overflow
CVE-2004-1373remotewindows19 Feb 2005
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RISK
open
Exploit-DBVexDay Proof
Thomson TCW690 - POST Password Validation
CVE-2005-0494remotehardware19 Feb 2005
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a d
23RISK
open
previouspage 680 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.