Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
PostgreSQL 7.x - Multiple Vulnerabilities
CVE-2005-0245doslinux01 Feb 2005
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large num
28RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.1/0.2/0.3 Credit Card Data - Remote Information Disclosure
CVE-2005-0229remotemultiple31 Jan 2005
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Xpand Rally 1.0.0.0 (Server/Clients) - Crash
CVE-2005-0325doswindows31 Jan 2005
Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application c
23RISK
open
Exploit-DBVexDay Proof
ncpfs < 2.2.6 (Gentoo / Linux) - Local Privilege Escalation
CVE-2010-0788locallinux30 Jan 2005
ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges v
23RISK
open
Exploit-DBVexDay Proof
Vim - 'mch_expand_wildcards()' Heap Buffer Overflow
CVE-2008-3432remotelinux29 Jan 2005
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted att
23RISK
open
Exploit-DBVexDay Proof
ngIRCd 0.6/0.7/0.8 - Remote Buffer Overflow
CVE-2005-0199doslinux28 Jan 2005
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a
28RISK
open
Exploit-DBVexDay Proof
IceWarp Web Mail 5.3 - login.html 'Username' Cross-Site Scripting
CVE-2005-0320webappsphp28 Jan 2005
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attack
23RISK
open
Exploit-DBVexDay Proof
IceWarp Web Mail 5.3 - 'accountsettings_add.html?accountid' Cross-Site Scripting
CVE-2005-0320webappsphp28 Jan 2005
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attack
23RISK
open
Exploit-DBVexDay Proof
WebWasher Classic 2.2/2.3 - HTTP CONNECT Unauthorized Access
CVE-2005-0316remotemultiple28 Jan 2005
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost f
23RISK
open
Exploit-DBVexDay Proof
Magic Winmail Server 4.0 (Build 1112) - 'download.php' Traversal Arbitrary File Access
CVE-2005-0313webappsphp27 Jan 2005
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload
23RISK
open
Exploit-DBVexDay Proof
War FTP Daemon 1.8 - Remote Denial of Service
CVE-2005-0312doswindows27 Jan 2005
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access
23RISK
open
Exploit-DBVexDay Proof
Magic Winmail Server 4.0 (Build 1112) - 'upload.php' Traversal Arbitrary File Upload
CVE-2005-0313webappsphp27 Jan 2005
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4 - 'uselib()' Local Privilege Escalation (2)
CVE-2004-1235locallinux27 Jan 2005
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.4
23RISK
open
Exploit-DBVexDay Proof
Berlios GPSD 2.7.x - Remote Format String
CVE-2004-1388remotelinux26 Jan 2005
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7
50RISK
open
Exploit-DBVexDay Proof
AWStats 6.0 < 6.2 - 'configdir' Remote Command Execution
CVE-2005-0116webappscgi25 Jan 2005
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacte
60RISK
open
Exploit-DBVexDay Proof
AWStats 6.0 < 6.2 - 'configdir' Remote Command Execution
CVE-2005-0116webappscgi25 Jan 2005
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacte
60RISK
open
Exploit-DBVexDay Proof
MercuryBoard 1.1 - Multiple Input Validation Vulnerabilities
CVE-2005-0307webappsphp25 Jan 2005
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
NullSoft Winamp 5.0.x - Variant 'IN_CDDA.dll' Remote Buffer Overflow (PoC)
CVE-2004-1150doswindows25 Jan 2005
Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - '.ANI' Downloader (MS05-002)
CVE-2005-0416remotewindows24 Jan 2005
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Window
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - '.ANI' Universal (MS05-002)
CVE-2005-0416remotewindows22 Jan 2005
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Window
35RISK
open
Exploit-DBVexDay Proof
Golden FTP Server 2.02b - Remote Buffer Overflow
CVE-2005-0566remotewindows22 Jan 2005
Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long R
28RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.3.7 - 'mRouter' Local Privilege Escalation
CVE-2005-0193localosx22 Jan 2005
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local us
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.3.7 - Input Validation Flaw 'parse_machfile()' Denial of Service
CVE-2005-0122dososx20 Jan 2005
20RISK
open
Exploit-DBVexDay Proof
Siteman 1.1 - User Database Privilege Escalation (2)
CVE-2005-0305webappsphp19 Jan 2005
CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users a
23RISK
open
Exploit-DBVexDay Proof
konversation irc client 0.15 - Multiple Vulnerabilities
CVE-2005-0129remotelinux19 Jan 2005
The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel nam
28RISK
open
Exploit-DBVexDay Proof
Siteman 1.1 - User Database Privilege Escalation (1)
CVE-2005-0305webappsphp19 Jan 2005
CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users a
23RISK
open
Exploit-DBVexDay Proof
NodeManager Professional 2.00 - Remote Buffer Overflow
CVE-2005-0185remotewindows18 Jan 2005
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a
23RISK
open
Exploit-DBVexDay Proof
Apple iTunes - Playlist Parsing Local Buffer Overflow
CVE-2005-0043localosx16 Jan 2005
Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2)
50RISK
open
Exploit-DBVexDay Proof
GeoBlog 1.0 - 'viewcat.php' SQL Injection
CVE-2006-0249webappsphp16 Jan 2005
SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
Exim 4.41 - 'dns_build_reverse' Local Buffer Overflow
CVE-2005-0021locallinux15 Jan 2005
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with
23RISK
open
previouspage 683 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.