Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
PhpGedView 2.61 - PHPInfo Information Disclosure
CVE-2004-0033webappsphp06 Jan 2004
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpi
23RISK
open
Exploit-DBVexDay Proof
Edimax AR-6004 ADSL Router - Management Interface Cross-Site Scripting
CVE-2004-1790remotehardware06 Jan 2004
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote at
23RISK
open
Exploit-DBVexDay Proof
PHPGedView 2.61 - Multiple Remote File Inclusions
CVE-2004-0030webappsphp06 Jan 2004
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php fo
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Validator (1)
CVE-2003-0985locallinux06 Jan 2004
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does
23RISK
open
Exploit-DBVexDay Proof
SnapStream PVS Lite 2.0 - Cross-Site Scripting
CVE-2004-0046remotewindows06 Jan 2004
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
ZYXEL ZyWALL 10 Management Interface - Cross-Site Scripting
CVE-2004-1789remotehardware06 Jan 2004
Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to in
28RISK
open
Exploit-DBVexDay Proof
PhpGedView 2.61 - Search Script Cross-Site Scripting
CVE-2004-0032webappsphp06 Jan 2004
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HT
23RISK
open
Exploit-DBVexDay Proof
HotNews 0.x - 'config[incdir]' Remote File Inclusion
CVE-2004-1796webappsphp05 Jan 2004
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
HotNews 0.x - 'hotnews-engine.inc.php3?config[header]' Remote File Inclusion
CVE-2004-1796webappsphp05 Jan 2004
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
phpBB 1.x/2.0.x - 'search.php?search_results' SQL Injection
CVE-2004-2350webappsphp04 Jan 2004
SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a
23RISK
open
Exploit-DBVexDay Proof
FreznoShop 1.2.3/1.3 - Search Script Cross-Site Scripting
CVE-2004-1797webappsphp04 Jan 2004
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to i
23RISK
open
Exploit-DBVexDay Proof
Webcam Corp Webcam Watchdog 1.0/1.1/3.63 Web Server - Remote Buffer Overflow
CVE-2004-1784remotewindows04 Jan 2004
Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long H
23RISK
open
Exploit-DBVexDay Proof
ASP-Nuke 1.0/1.2/1.3 - Remote User Database Access
CVE-2004-1788webappsasp04 Jan 2004
ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which all
23RISK
open
Exploit-DBVexDay Proof
ASPApp PortalApp - Remote User Database Access
CVE-2004-1786webappsasp04 Jan 2004
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
EasyDynamicPages 1.0 - 'config_page.php' PHP Remote File Inclusion
CVE-2004-0073webappsphp02 Jan 2004
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote
23RISK
open
Exploit-DBVexDay Proof
Athena Web Registration - Remote Command Execution
CVE-2004-1782webappsphp02 Jan 2004
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters
28RISK
open
Exploit-DBVexDay Proof
Surfnet 1.31 - CMD_CREDITCARD_CHARGE Denial of Service
CVE-2004-1781doswindows02 Jan 2004
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CRED
23RISK
open
Exploit-DBVexDay Proof
YaSoft Switch Off 2.3 - 'swnet.dll' Remote Buffer Overflow
CVE-2004-1793remotewindows02 Jan 2004
Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execu
23RISK
open
Exploit-DBVexDay Proof
YaSoft Switch Off 2.3 - Large Packet Remote Denial of Service
CVE-2004-1792doshardware02 Jan 2004
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via
23RISK
open
Exploit-DBVexDay Proof
XSOK 1.02 - '-xsokdir' Local Buffer Overflow Game
CVE-2004-0074locallinux02 Jan 2004
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RISK
open
Exploit-DBVexDay Proof
XSOK 1.0 2 - 'LANG Environment' Local Buffer Overrun
CVE-2004-0074locallinux30 Dec 2003
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2000 - showHelp '.CHM' File Execution (MS03-004)
CVE-2003-1041doswindows30 Dec 2003
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal a
35RISK
open
Exploit-DBVexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (2)
CVE-2003-1200remotewindows29 Dec 2003
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RISK
open
Exploit-DBVexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (1)
CVE-2003-1200doswindows29 Dec 2003
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - Failure To Log Undocumented TRACK Requests
CVE-2003-1566remotewindows29 Dec 2003
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote a
28RISK
open
Exploit-DBVexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (2)
CVE-2003-1307locallinux26 Dec 2003
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RISK
open
Exploit-DBVexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (1)
CVE-2003-1307locallinux26 Dec 2003
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RISK
open
Exploit-DBVexDay Proof
KnowledgeBuilder 2.0/2.1/3.0 - Remote File Inclusion
CVE-2003-1131webappsphp24 Dec 2003
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote at
23RISK
open
Exploit-DBVexDay Proof
Opera Browser 6.0 6 - URI Display Obfuscation
CVE-2003-1025remotewindows23 Dec 2003
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 6.x - 'Category' SQL Injection
CVE-2004-0269webappsphp23 Dec 2003
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary S
23RISK
open
previouspage 718 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.