Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Nokia Electronic Documentation 5.0 - Path Disclosure
CVE-2003-0802remotewindows15 Sep 2003
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root,
23RISK
open
Exploit-DBVexDay Proof
Nokia Electronic Documentation 5.0 - Cross-Site Scripting
CVE-2003-0801remotewindows15 Sep 2003
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute
28RISK
open
Exploit-DBVexDay Proof
MySQL 3.23.x/4.0.x - Remote Buffer Overflow
CVE-2003-0780remotelinux14 Sep 2003
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers wit
45RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'RPC DCOM' Scanner (MS03-039)
CVE-2003-0605remotewindows12 Sep 2003
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open
Exploit-DBVexDay Proof
Roger Wilco 1.x - Client Data Buffer Overflow
CVE-2003-0767remotemultiple10 Sep 2003
Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Script Execution
CVE-2003-0816remotewindows10 Sep 2003
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - window.open Search Pane Cross-Zone Scripting
CVE-2003-0816remotewindows10 Sep 2003
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind
35RISK
open
Exploit-DBVexDay Proof
MySQL 3.23.x/4.0.x - Password Handler Buffer Overflow
CVE-2003-0780doslinux10 Sep 2003
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers wit
45RISK
open
Exploit-DBVexDay Proof
Escapade 0.2.1 Beta Scripting Engine - 'PAGE' Cross-Site Scripting
CVE-2003-0763webappscgi09 Sep 2003
Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
NullSoft Winamp 2.81/2.91/3.0/3.1 - MIDI Plugin 'IN_MIDI.dll' Track Data Size Buffer Overflow (PoC)
CVE-2003-0765doswindows08 Sep 2003
The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a
23RISK
open
Exploit-DBVexDay Proof
ICQ 2003 - Webfront Guestbook Cross-Site Scripting
CVE-2003-0769webappsasp08 Sep 2003
Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to inse
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - XML Page Object Type Validation (MS03-040)
CVE-2003-0809remotewindows08 Sep 2003
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data bindi
28RISK
open
Exploit-DBVexDay Proof
FTP Desktop 3.5 - Banner Parsing Buffer Overflow
CVE-2003-0766doswindows08 Sep 2003
Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious se
23RISK
open
Exploit-DBVexDay Proof
FTP Desktop 3.5 - FTP 331 Server Response Buffer Overflow
CVE-2003-0766doswindows08 Sep 2003
Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious se
23RISK
open
Exploit-DBVexDay Proof
Mah-Jong 1.4/1.6 - Server Remote Denial of Service
CVE-2003-0706doslinux07 Sep 2003
Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - Browser Popup Window Object Type Validation
CVE-2003-0838remotewindows07 Sep 2003
Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creati
35RISK
open
Exploit-DBVexDay Proof
Mah-Jong 1.4 - Client/Server Remote sscanf() Buffer Overflow
CVE-2003-0705remotelinux07 Sep 2003
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
23RISK
open
Exploit-DBVexDay Proof
Microsoft WordPerfect Document Converter (Windows NT4 Workstation SP5/SP6 French) - File Template Buffer Overflow (MS03-036)
CVE-2003-0666remotewindows06 Sep 2003
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data o
28RISK
open
Exploit-DBVexDay Proof
Stunnel 3.24/4.00 - Daemon Hijacking
CVE-2003-0740locallinux05 Sep 2003
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to
23RISK
open
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 3.4/4.0 - FTP Command Buffer Overrun
CVE-2003-0772remotewindows04 Sep 2003
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly e
45RISK
open
Exploit-DBVexDay Proof
Microsoft Access 97/2000/2002 Snapshot Viewer - ActiveX Control Parameter Buffer Overflow
CVE-2003-0665remotewindows03 Sep 2003
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote
35RISK
open
Exploit-DBVexDay Proof
Microsoft Visual Basic For Applications SDK 5.0/6.0/6.2/6.3 - Document Handling Buffer Overrun
CVE-2003-0347remotewindows03 Sep 2003
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3
35RISK
open
Exploit-DBVexDay Proof
Microsoft WordPerfect - Converter Buffer Overrun
CVE-2003-0666localwindows03 Sep 2003
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data o
28RISK
open
Exploit-DBVexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Information Disclosure
CVE-2003-0747remotemultiple30 Aug 2003
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensiti
23RISK
open
Exploit-DBVexDay Proof
sap internet transaction server 4620.2.0.323011 build 46b.323011 - Directory Traversal
CVE-2003-0748remotemultiple30 Aug 2003
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote a
23RISK
open
Exploit-DBVexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Cross-Site Scripting
CVE-2003-0749remotemultiple30 Aug 2003
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows r
23RISK
open
Exploit-DBVexDay Proof
Linux pam_lib_smb < 1.1.6 - '/bin/login' Remote Overflow
CVE-2003-0686remotelinux29 Aug 2003
Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote at
28RISK
open
Exploit-DBVexDay Proof
GtkFtpd 1.0.4 - Remote Buffer Overflow
CVE-2003-0755remotelinux28 Aug 2003
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating
23RISK
open
Exploit-DBVexDay Proof
Tellurian TftpdNT 1.8/2.0 - 'Filename' Buffer Overrun
CVE-2003-0729remotewindows27 Aug 2003
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a lon
28RISK
open
Exploit-DBVexDay Proof
eNdonesia 8.2/8.3 - 'Mod' Cross-Site Scripting
CVE-2003-1317webappsphp27 Aug 2003
Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web scr
23RISK
open
previouspage 724 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.