Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,017cataloged exploits
35,920CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Sami FTP Server 1.1.3 - Library Crafted GET Remote Denial of Service
CVE-2004-2082doswindows13 Feb 2004
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsyste
23RISK
open
Exploit-DBVexDay Proof
Sami FTP Server 1.1.3 - Invalid Command Argument Local Denial of Service
CVE-2004-2081doswindows13 Feb 2004
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - ITS Protocol Zone Bypass (MS04-013)
CVE-2004-0380remotewindows13 Feb 2004
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to
35RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0 - 'search.php' Cross-Site Scripting
CVE-2004-2076webappsphp13 Feb 2004
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
KarjaSoft Sami HTTP Server 1.0.4 - GET Buffer Overflow
CVE-2004-0292remotewindows13 Feb 2004
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and pos
23RISK
open
Exploit-DBVexDay Proof
Macallan Mail Solution Macallan Mail Solution 2.8.4.6 (Build 260) - Web Interface Authentication Bypass
CVE-2004-2071webappsphp12 Feb 2004
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat
23RISK
open
Exploit-DBVexDay Proof
XFree86 4.x - CopyISOLatin1Lowered Font_Name Buffer Overflow
CVE-2004-0084doslinux12 Feb 2004
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, a
28RISK
open
Exploit-DBVexDay Proof
Crob FTP Server 3.5.2 - Remote Denial of Service
CVE-2004-0282doswindows12 Feb 2004
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disco
23RISK
open
Exploit-DBVexDay Proof
VisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File Inclusion
CVE-2004-0132webappsphp11 Feb 2004
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
CVE-2004-0132webappsphp11 Feb 2004
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
BolinTech DreamFTP Server 1.2 (1.02/TryFTP 1.0.0.1) - Remote User Name Format String
CVE-2004-2074remotewindows11 Feb 2004
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISK
open
Exploit-DBVexDay Proof
BosDev BosDates 3.x - SQL Injection
CVE-2004-0275webappsphp11 Feb 2004
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensi
23RISK
open
Exploit-DBVexDay Proof
Monkey HTTP Daemon 0.x - Missing Host Field Denial of Service
CVE-2004-0276doswindows11 Feb 2004
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
Maxwebportal 1.3x - Personal Message 'SendTo' Cross-Site Scripting
CVE-2004-0271webappsasp10 Feb 2004
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
Maxwebportal 1.3x - 'down.asp' HTTP_REFERER Cross-Site Scripting
CVE-2004-0271webappsasp10 Feb 2004
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
EvolutionX - Multiple Remote Buffer Overflow Vulnerabilities
CVE-2004-0268doswindows10 Feb 2004
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1)
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP - HCP URI Handler Arbitrary Command Execution
CVE-2004-0474remotewindows09 Feb 2004
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" ar
28RISK
open
Exploit-DBVexDay Proof
Caucho Technology Resin 2.1.12 - Directory Listings Disclosure
CVE-2004-0281remotelinux09 Feb 2004
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-I
23RISK
open
Exploit-DBVexDay Proof
Nadeo Game Engine - Remote Denial of Service
CVE-2004-2077doslinux09 Feb 2004
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
Shaun2k2 Palmhttpd Server 3.0 - Remote Denial of Service
CVE-2004-0264doswindows09 Feb 2004
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP
23RISK
open
Exploit-DBVexDay Proof
Sambar Server 6.0 - 'results.stm' POST Buffer Overflow
CVE-2004-2086doswindows09 Feb 2004
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RISK
open
Exploit-DBVexDay Proof
Red-M Red-Alert 3.1 - Remote Denial of Service
CVE-2004-2078doshardware09 Feb 2004
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss o
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.x 'Reviews' Module - Cross-Site Scripting
CVE-2004-0265webappsphp09 Feb 2004
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.x - Public Message SQL Injection
CVE-2004-0266webappsphp09 Feb 2004
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote
23RISK
open
Exploit-DBVexDay Proof
Samba 2.2.8 (Linux Kernel 2.6 / Debian / Mandrake) - Share Privilege Escalation
CVE-2004-0186locallinux09 Feb 2004
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting
23RISK
open
Exploit-DBVexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
CVE-2004-0270doslinux09 Feb 2004
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RISK
open
Exploit-DBVexDay Proof
BolinTech DreamFTP Server 1.0 - User Name Format String
CVE-2004-0277doswindows07 Feb 2004
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - LoadPicture File Enumeration
CVE-2004-2090remotewindows07 Feb 2004
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via
28RISK
open
Exploit-DBVexDay Proof
OpenJournal 2.0 - Authentication Bypassing
CVE-2004-0261webappscgi06 Feb 2004
oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel vi
23RISK
open
Exploit-DBVexDay Proof
Linux VServer Project 1.2x - Chroot Breakout
CVE-2004-2073locallinux06 Feb 2004
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside
23RISK
open
previouspage 714 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.