Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Thomson TCW690 Cable Modem ST42.03.0a - GET Denial of Service
CVE-2003-1085doshardware19 Feb 2005
The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a deni
23RISK
open
Exploit-DBVexDay Proof
SHOUTcast 1.9.4 (Windows) - File Request Format String Remote Overflow
CVE-2004-1373remotewindows19 Feb 2005
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RISK
open
Exploit-DBVexDay Proof
Knox Arkeia Backup Client 5.3.3 Type 77 (OSX) - Overflow (Metasploit)
CVE-2005-0491remoteosx18 Feb 2005
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RISK
open
Exploit-DBVexDay Proof
TrackerCam 5.12 - 'ComGetLogFile.php3?fm' Traversal Arbitrary File Access
CVE-2005-0479webappsphp18 Feb 2005
Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read
23RISK
open
Exploit-DBVexDay Proof
Knox Arkeia Server Backup 5.3.x - Remote Code Execution
CVE-2005-0491remotemultiple18 Feb 2005
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RISK
open
Exploit-DBVexDay Proof
Medal of Honor Spearhead (Linux) - Server Remote Buffer Overflow
CVE-2004-0735remotelinux18 Feb 2005
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISK
open
Exploit-DBVexDay Proof
3Com 3CDaemon FTP - Unauthorized 'USER' Remote Buffer Overflow
CVE-2005-0277remotewindows18 Feb 2005
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RISK
open
Exploit-DBVexDay Proof
paFaq beta4 - 'answer.php?offset' SQL Injection
CVE-2005-0475webappsphp17 Feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
paFaq beta4 - 'question.php' Multiple SQL Injections
CVE-2005-0475webappsphp17 Feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
paFaq beta4 - 'comment.php' Multiple SQL Injections
CVE-2005-0475webappsphp17 Feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
3Com FTP Server 2.0 - Remote Overflow
CVE-2005-0277remotewindows17 Feb 2005
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RISK
open
Exploit-DBVexDay Proof
BibORB 1.3.2 - 'index.php' Traversal Arbitrary File Manipulation
CVE-2005-0253webappsphp17 Feb 2005
Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
BibORB 1.3.2 - Add Database 'Description' Cross-Site Scripting
CVE-2005-0251webappsphp17 Feb 2005
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RISK
open
Exploit-DBVexDay Proof
paFaq beta4 - 'search.php?search_item' SQL Injection
CVE-2005-0475webappsphp17 Feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
BibORB 1.3.2 Login Module - Multiple SQL Injections
CVE-2005-0252webappsphp17 Feb 2005
SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
BibORB 1.3.2 - 'bibindex.php?search' Cross-Site Scripting
CVE-2005-0251webappsphp17 Feb 2005
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RISK
open
Exploit-DBVexDay Proof
Microsoft ASP.NET 1.0/1.1 - Unicode Character Conversion Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0452webappsasp16 Feb 2005
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attacker
28RISK
open
Exploit-DBVexDay Proof
Typespeed 0.4.1 - Local Format String
CVE-2005-0105locallinux16 Feb 2005
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
23RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'importcc.php' CSV File SQL Injection
CVE-2005-0410webappsphp15 Feb 2005
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via th
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (2)
CVE-2005-0429webappsphp15 Feb 2005
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'importcc.php' Arbitrary Database Injection
CVE-2005-0409webappsphp15 Feb 2005
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'uploadcc.php' Arbitrary Database Injection
CVE-2005-0409webappsphp15 Feb 2005
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RISK
open
Exploit-DBVexDay Proof
Savant Web Server 3.1 (French Windows)- Remote Buffer Overflow
CVE-2005-0338remotewindows15 Feb 2005
Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.
23RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - Arbitrary Local PHP File Inclusion
CVE-2005-0411webappsphp15 Feb 2005
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to
23RISK
open
Exploit-DBVexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Traversal Arbitrary File Access
CVE-2005-0442webappsphp14 Feb 2005
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via th
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (1)
CVE-2005-0429webappsphp14 Feb 2005
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RISK
open
Exploit-DBVexDay Proof
AWStats 6.4 - Denial of Service
CVE-2005-0435doscgi14 Feb 2005
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmo
23RISK
open
Exploit-DBVexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Cross-Site Scripting
CVE-2005-0443webappsphp14 Feb 2005
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-
23RISK
open
Exploit-DBVexDay Proof
AWStats 6.4 - Denial of Service
CVE-2005-0436doscgi14 Feb 2005
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of
23RISK
open
Exploit-DBVexDay Proof
CA BrightStor ARCserve Backup - Remote Buffer Overflow (PoC)
CVE-2005-2535doslinux12 Feb 2005
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execu
60RISK
open
previouspage 681 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.