Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Gattaca Server 2003 POP3 - Denial of Service
CVE-2004-2520dosmultiple15 Jul 2004
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio
23RISK
open
Exploit-DBVexDay Proof
Gattaca Server 2003 - Null Byte Full Path Disclosure
CVE-2004-2518webappscgi15 Jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open
Exploit-DBVexDay Proof
BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting
CVE-2004-1441webappscgi15 Jul 2004
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Gattaca Server 2003 - 'web.tmpl?Language' CPU Consumption (Denial of Service)
CVE-2004-2519dosmultiple15 Jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif
23RISK
open
Exploit-DBVexDay Proof
Gattaca Server 2003 - Cross-Site Scripting
CVE-2004-2522webappscgi15 Jul 2004
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a
23RISK
open
Exploit-DBVexDay Proof
Gattaca Server 2003 - 'Language' Path Exposure
CVE-2004-2518webappscgi15 Jul 2004
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISK
open
Exploit-DBVexDay Proof
PHP 4.x/5.0 - 'Strip_Tags()' Function Bypass
CVE-2004-0595remotephp14 Jul 2004
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Utility Manager Privilege Escalation (MS04-019)
CVE-2004-0213localwindows14 Jul 2004
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISK
open
Exploit-DBVexDay Proof
IBM Lotus Notes 6.0/6.5 - Multiple Java Applet Vulnerabilities
CVE-2004-2280dosunix13 Jul 2004
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial o
23RISK
open
Exploit-DBVexDay Proof
Mozilla Browser 0.9/1.x Cache File - Multiple Vulnerabilities
CVE-2004-0760remotewindows13 Jul 2004
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null charact
23RISK
open
Exploit-DBVexDay Proof
Moodle Help Script 1.x - Cross-Site Scripting
CVE-2004-0725webappsphp13 Jul 2004
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit
23RISK
open
Exploit-DBVexDay Proof
IM-Switch - Insecure Temporary File Handling Symbolic Link
CVE-2004-2502locallinux13 Jul 2004
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Remote Wscript.Shell
CVE-2004-0549remotewindows13 Jul 2004
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6,
35RISK
open
Exploit-DBVexDay Proof
WebSTAR FTP Server 5.3.2 (OSX) - USER Overflow (Metasploit)
CVE-2004-0695remoteosx13 Jul 2004
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Popup.show Mouse Event Hijacking
CVE-2004-0841remotewindows12 Jul 2004
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.sho
35RISK
open
Exploit-DBVexDay Proof
Norton AntiVirus - Denial of Service
CVE-2004-0683doswindows12 Jul 2004
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a com
23RISK
open
Exploit-DBVexDay Proof
Code-Crafters Ability Mail Server 1.18 - 'errormsg' Cross-Site Scripting
CVE-2004-2494remotemultiple12 Jul 2004
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
phpBB 2.0.x - 'viewtopic.php' PHP Script Injection
CVE-2004-1315webappsphp12 Jul 2004
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - JavaScript Method Assignment Cross-Domain Scripting
CVE-2004-0727remotewindows12 Jul 2004
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows
35RISK
open
Exploit-DBVexDay Proof
MySQL 4.1/5.0 - Zero-Length Password Authentication Bypass
CVE-2004-0627remotemultiple10 Jul 2004
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication v
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Remote Application.Shell
CVE-2004-2291remotewindows09 Jul 2004
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script
28RISK
open
Exploit-DBVexDay Proof
Mozilla 1.7 - External Protocol Handler
CVE-2004-0648remotewindows08 Jul 2004
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Style Tag Comment Memory Corruption
CVE-2004-0842remotewindows08 Jul 2004
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service
35RISK
open
Exploit-DBVexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site Scripting
CVE-2004-0681webappsasp07 Jul 2004
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffic
23RISK
open
Exploit-DBVexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_gatewayPayPal.asp' Price Manipulation
CVE-2004-0682webappsasp07 Jul 2004
comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to c
23RISK
open
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - 'action' Cross-Site Scripting
CVE-2004-2444webappsphp06 Jul 2004
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - Cookie Manipulation Authentication Bypass
CVE-2004-2443webappsphp06 Jul 2004
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie se
23RISK
open
Exploit-DBVexDay Proof
Jaws 0.2/0.3 - 'gadget' Traversal Arbitrary File Access
CVE-2004-2445webappsphp06 Jul 2004
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..
23RISK
open
Exploit-DBVexDay Proof
Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure
CVE-2004-0671webappscgi05 Jul 2004
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t
23RISK
open
Exploit-DBVexDay Proof
12Planet Chat Server 2.9 - Cross-Site Scripting
CVE-2004-0678remotemultiple05 Jul 2004
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to exec
23RISK
open
previouspage 699 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.