Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Exim 4.41 - 'dns_build_reverse' Local Buffer Overflow
CVE-2005-0021locallinux15 Jan 2005
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with
23RISK
open
Exploit-DBVexDay Proof
Breed patch #1 - Zero-Length Remote Crash
CVE-2005-0382doswindows13 Jan 2005
Breed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP pack
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Improper Token Validation Privilege Escalation
CVE-2004-0894localwindows11 Jan 2005
LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly vali
23RISK
open
Exploit-DBVexDay Proof
Veritas Backup Exec Agent 8.x/9.x - Browser Overflow
CVE-2004-1172remotewindows11 Jan 2005
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9
60RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.29-rc2 - 'uselib()' Local Privilege Escalation (1)
CVE-2004-1235locallinux07 Jan 2005
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.4
23RISK
open
Exploit-DBVexDay Proof
QwikiWiki - Directory Traversal
CVE-2005-0283webappsphp04 Jan 2005
Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (do
23RISK
open
Exploit-DBVexDay Proof
SOLDNER Secret Wars 30830 - Denial of Service
CVE-2005-0280doswindows04 Jan 2005
Format string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of servic
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - WINS Remote Code Execution
CVE-2004-0567remotewindows31 Dec 2004
The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Ser
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NetDDE Remote Buffer Overflow (MS04-031)
CVE-2004-0206remotewindows31 Dec 2004
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and
60RISK
open
Exploit-DBVexDay Proof
PHP 4.3.7 - 'openlog()' Remote Buffer Overflow
CVE-2003-0172remotewindows28 Dec 2004
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISK
open
Exploit-DBVexDay Proof
Netcat 1.1 - '-e' Switch Remote Buffer Overflow
CVE-2004-1317remotewindows26 Dec 2004
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - '.ANI' File Parsing Crash
CVE-2004-1305doswindows25 Dec 2004
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Window
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer (Windows XP SP2) - HTML Help Control Local Zone Bypass
CVE-2004-1043remotewindows25 Dec 2004
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics"
35RISK
open
Exploit-DBVexDay Proof
Solaris 7/8/9 CDE LibDTHelp - Local Buffer Overflow (1)
CVE-2003-0834localsolaris24 Dec 2004
Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARC
23RISK
open
Exploit-DBVexDay Proof
Solaris 8/9 passwd - 'circ()' Local Privilege Escalation
CVE-2004-0360localsolaris24 Dec 2004
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vecto
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 2.6.7-rc3 (Slackware 9.1 / Debian 3.0) - 'sys_chown()' Group Ownership Alteration Privilege Escalation
CVE-2004-0497locallinux24 Dec 2004
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported fi
23RISK
open
Exploit-DBVexDay Proof
Solaris 2.6/7/8/9 (SPARC) - 'ld.so.1' Local Privilege Escalation
CVE-2003-0609localsolaris24 Dec 2004
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root pri
23RISK
open
Exploit-DBVexDay Proof
Solaris 7/8/9 CDE LibDTHelp - Local Buffer Overflow (2)
CVE-2003-0834localsolaris24 Dec 2004
Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARC
23RISK
open
Exploit-DBVexDay Proof
Solaris 2.5.1/2.6/7/8 rlogin (SPARC) - '/bin/login' Remote Buffer Overflow
CVE-2001-0797remotesolaris24 Dec 2004
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - 'winhlp32' Phrase Integer Overflow
CVE-2004-1306remotewindows23 Dec 2004
Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows
28RISK
open
Exploit-DBVexDay Proof
SHOUTcast DNAS/Linux 1.9.4 - Format String Remote Overflow
CVE-2004-1373remotelinux23 Dec 2004
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RISK
open
Exploit-DBVexDay Proof
Wirtualna Polska WPKontakt 3.0.1 - Remote Script Execution
CVE-2004-1418webappscgi23 Dec 2004
Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Seattle Lab Mail (SLmail) 5.5 - POP3 'PASS' Remote Buffer Overflow (3)
CVE-2003-0264remotewindows22 Dec 2004
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
Exploit-DBVexDay Proof
Snort 2.1/2.2 - DecodeTCPOptions Remote Denial of Service (1)
CVE-2004-2652doslinux22 Dec 2004
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbo
28RISK
open
Exploit-DBVexDay Proof
Snort 2.1/2.2 - DecodeTCPOptions Remote Denial of Service (2)
CVE-2004-2652doslinux22 Dec 2004
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbo
28RISK
open
Exploit-DBVexDay Proof
phpMyChat 0.14.5 - Remote Improper File Permissions
CVE-2004-2718webappsphp22 Dec 2004
PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive in
23RISK
open
Exploit-DBVexDay Proof
2BGal 2.5.1 - SQL Injection
CVE-2004-1415webappsphp22 Dec 2004
SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote att
23RISK
open
Exploit-DBVexDay Proof
AIX 4.3/5.1 < 5.3 - 'lsmcode' Execution Privilege Escalation
CVE-2004-1054localaix21 Dec 2004
Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privile
23RISK
open
Exploit-DBVexDay Proof
Seattle Lab Mail (SLmail) 5.5 - POP3 'PASS' Remote Buffer Overflow (2)
CVE-2003-0264remotewindows21 Dec 2004
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
Exploit-DBVexDay Proof
IBM AIX 5.x - 'Diag' Local Privilege Escalation
CVE-2004-1329localaix20 Dec 2004
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd
23RISK
open
previouspage 684 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.