Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
SnipSnap 0.5.2 - HTTP Response Splitting
CVE-2004-1470remotemultiple14 Sep 2004
CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTT
23RISK
open
Exploit-DBVexDay Proof
QNX Photon input-cfg - '-s' Overflow
CVE-2004-1681dosunix13 Sep 2004
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI f
23RISK
open
Exploit-DBVexDay Proof
QNX Photon phlocale - '-s' Overflow
CVE-2004-1681dosunix13 Sep 2004
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI f
23RISK
open
Exploit-DBVexDay Proof
QNX Photon phrelay-cfg - '-s' Overflow
CVE-2004-1681dosunix13 Sep 2004
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI f
23RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTP Server < 5.2 - Remote Denial of Service
CVE-2004-1675doswindows13 Sep 2004
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQU
28RISK
open
Exploit-DBVexDay Proof
PerlDesk Language Variable - Server-Side Script Execution
CVE-2004-1678webappscgi13 Sep 2004
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files a
23RISK
open
Exploit-DBVexDay Proof
QNX Photon pkg-installer - '-s' Overflow
CVE-2004-1681dosunix13 Sep 2004
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI f
23RISK
open
Exploit-DBVexDay Proof
BlackJumboDog FTP Server 3.6.1 - Remote Buffer Overflow
CVE-2004-1439remotewindows12 Sep 2004
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
28RISK
open
Exploit-DBVexDay Proof
CDRecord's ReadCD - '$RSH exec()' SUID Shell Creation
CVE-2004-0806locallinux11 Sep 2004
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before execu
23RISK
open
Exploit-DBVexDay Proof
Apache mod_ssl 2.0.x - Remote Denial of Service
CVE-2004-0751doslinux10 Sep 2004
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows
45RISK
open
Exploit-DBVexDay Proof
Citadel/UX 6.23 - Remote USER Directive
CVE-2004-1705remotelinux09 Sep 2004
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RISK
open
Exploit-DBVexDay Proof
Trillian 0.74i MSN Module - Remote Buffer Overflow
CVE-2004-1666remotewindows08 Sep 2004
Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long strin
23RISK
open
Exploit-DBVexDay Proof
PSNews 1.1 - 'No' Cross-Site Scripting
CVE-2004-1665webappsphp05 Sep 2004
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
Call of Duty 1.4 - Denial of Service
CVE-2004-1664dosmultiple05 Sep 2004
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2
23RISK
open
Exploit-DBVexDay Proof
Oracle Database Server 8.1.7/9.0.x - ctxsys.driload Access Validation
CVE-2004-0637remotemultiple03 Sep 2004
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the
28RISK
open
Exploit-DBVexDay Proof
AOL Instant Messenger AIM - 'Away' Message Remote (2)
CVE-2004-0636remotewindows02 Sep 2004
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.
50RISK
open
Exploit-DBVexDay Proof
Courier-IMAP 3.0.2-r1 - 'auth_debug()' Remote Format String
CVE-2004-0777remotebsd02 Sep 2004
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when l
28RISK
open
Exploit-DBVexDay Proof
CuteNews 0.88/1.3.x - 'index.php' Cross-Site Scripting
CVE-2004-1659webappsphp02 Sep 2004
Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Adminis
23RISK
open
Exploit-DBVexDay Proof
SiteCubed MailWorks Professional - Authentication Bypass
CVE-2004-1661webappsphp02 Sep 2004
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.x/0.9.x Comment Module - 'CM_pid' Cross-Site Scripting
CVE-2004-1655webappsphp01 Sep 2004
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
IBM DB2 DTS To String Conversion - Denial of Service
CVE-2005-4869doslinux01 Sep 2004
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application cra
23RISK
open
Exploit-DBVexDay Proof
Comersus Cart 5.0 - HTTP Response Splitting
CVE-2004-1656webappsasp01 Sep 2004
CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting
23RISK
open
Exploit-DBVexDay Proof
Newtelligence DasBlog 1.x - Request Log HTML Injection
CVE-2004-1657webappsphp01 Sep 2004
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attac
23RISK
open
Exploit-DBVexDay Proof
IBM DB2 - Universal Database Information Disclosure
CVE-2005-4868localwindows01 Sep 2004
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, whic
23RISK
open
Exploit-DBVexDay Proof
Titan FTP Server - Long Command Heap Overflow
CVE-2004-1641remotewindows31 Aug 2004
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) vi
38RISK
open
Exploit-DBVexDay Proof
Web Animations Password Protect - Multiple Input Validation Vulnerabilities
CVE-2004-1647webappsasp31 Aug 2004
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass a
23RISK
open
Exploit-DBVexDay Proof
D-Link DCS-900 Camera - Remote IP Address Changer
CVE-2004-1650remotehardware31 Aug 2004
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the
23RISK
open
Exploit-DBVexDay Proof
Ground Control 1.0.0.7 - 'Server/Client' Denial of Service
CVE-2004-1751doswindows31 Aug 2004
Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or se
23RISK
open
Exploit-DBVexDay Proof
WFTPD Pro Server 3.21 - MLST Remote Denial of Service
CVE-2004-1642doswindows31 Aug 2004
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST
23RISK
open
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 5.0.x - CD Command Malformed File Path Remote Denial of Service
CVE-2004-1643doswindows30 Aug 2004
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that cont
23RISK
open
previouspage 694 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.