Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
@lexPHPTeam @lex Guestbook 3.12 - PHP Remote File Inclusion
CVE-2004-1554webappsphp27 Sep 2004
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG GDI+ Bind/Reverse/Admin/File Download
CVE-2004-0200remotewindows27 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG GDI+ Remote Heap Overflow (MS04-028)
CVE-2004-0200remotewindows25 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Download Shellcode (MS04-028)
CVE-2004-0200remotewindows25 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
PopMessenger 1.60 - Remote Denial of Service
CVE-2004-1698doswindows23 Sep 2004
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of s
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Administrator (MS04-028)
CVE-2004-0200remotewindows23 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
Sophos Anti-Virus 3.x - Reserved MS-DOS Name Scan Evasion
CVE-2004-0552remotewindows22 Sep 2004
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device na
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG GDI+ Overflow Shellcode
CVE-2004-0200remotewindows22 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
Alt-N MDaemon 6.5.1 - IMAP/SMTP Remote Buffer Overflow
CVE-2004-1546remotewindows22 Sep 2004
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - JPEG Processing Buffer Overrun (MS04-028)
CVE-2004-0200doswindows22 Sep 2004
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlu
35RISK
open
Exploit-DBVexDay Proof
EmuLive Server4 - Authentication Bypass / Denial of Service
CVE-2004-1695doscgi21 Sep 2004
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administrati
28RISK
open
Exploit-DBVexDay Proof
Emulive Server4 Build 7560 - Remote Denial of Service
CVE-2004-1696doswindows21 Sep 2004
EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via
23RISK
open
Exploit-DBVexDay Proof
LaTeX2rtf 1.9.15 - Remote Buffer Overflow
CVE-2004-2167remotelinux21 Sep 2004
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RISK
open
Exploit-DBVexDay Proof
Pinnacle ShowCenter 1.51 - Web Interface Skin Denial of Service
CVE-2004-1699dosphp21 Sep 2004
SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors)
23RISK
open
Exploit-DBVexDay Proof
SudoEdit 1.6.8 - Local Change Permission
CVE-2004-1689locallinux21 Sep 2004
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbit
23RISK
open
Exploit-DBVexDay Proof
Mambo Open Source 4.5.1 (1.0.9) - 'Function.php' Arbitrary Command Execution
CVE-2004-1693webappsphp20 Sep 2004
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
TUTOS - 'app_new.php?t' Cross-Site Scripting
CVE-2004-2162webappsphp20 Sep 2004
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
TUTOS - 'file_overview.php?link_id' SQL Injection
CVE-2004-2161webappsphp20 Sep 2004
SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Mambo Open Source 4.5.1 (1.0.9) - Cross-Site Scripting
CVE-2004-1692webappsphp20 Sep 2004
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Pigeon Server 3.02.0143 - Denial of Service
CVE-2004-1688doswindows19 Sep 2004
Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumpt
23RISK
open
Exploit-DBVexDay Proof
CDRecord's ReadCD - Local Privilege Escalation
CVE-2004-0806locallinux19 Sep 2004
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu
23RISK
open
Exploit-DBVexDay Proof
Remository - SQL Injection
CVE-2004-2143webappsphp18 Sep 2004
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remot
23RISK
open
Exploit-DBVexDay Proof
Google Toolbar 1.1.x - About.HTML HTML Injection
CVE-2004-2475remotewindows17 Sep 2004
Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
DNS4Me 3.0 - Denial of Service / Cross-Site Scripting
CVE-2004-1691dosmultiple17 Sep 2004
The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a
23RISK
open
Exploit-DBVexDay Proof
Snitz Forums 2000 - 'down.asp' HTTP Response Splitting
CVE-2004-1687webappsasp16 Sep 2004
CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response S
23RISK
open
Exploit-DBVexDay Proof
Alt-N MDaemon 6.5.1 SMTP Server - Multiple Command Remote Overflows
CVE-2004-1546remotewindows16 Sep 2004
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a
35RISK
open
Exploit-DBVexDay Proof
PHP-Nuke - SQL Injection Edit/Save Messages
CVE-2004-1932webappsphp16 Sep 2004
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
myserver 0.7 - Directory Traversal
CVE-2004-2516remotewindows15 Sep 2004
Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET
23RISK
open
Exploit-DBVexDay Proof
PHP 4.x/5.0.1 - PHP_Variables Remote Memory Disclosure
CVE-2004-0958remotephp15 Sep 2004
php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or
23RISK
open
Exploit-DBVexDay Proof
CUPS 1.1.x - UDP Packet Remote Denial of Service
CVE-2004-0558doslinux15 Sep 2004
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RISK
open
previouspage 693 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.