Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access
CVE-2003-0752webappsphp26 Aug 2003
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to b
23RISK
open
Exploit-DBVexDay Proof
Real Server 7/8/9 (Windows / Linux) - Remote Code Execution
CVE-2003-0725remotemultiple25 Aug 2003
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetwor
35RISK
open
Exploit-DBVexDay Proof
OptiSoft Blubster 2.5 - Remote Denial of Service
CVE-2003-0760doswindows25 Aug 2003
Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.
23RISK
open
Exploit-DBVexDay Proof
Avant Browser 8.0.2 - 'HTTP Request' Buffer Overflow (PoC)
CVE-2003-1321dosmultiple21 Aug 2003
Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Object Data Remote (MS03-032)
CVE-2003-0701remotewindows21 Aug 2003
Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) all
35RISK
open
Exploit-DBVexDay Proof
RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution
CVE-2003-0726remotewindows19 Aug 2003
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation wit
23RISK
open
Exploit-DBVexDay Proof
DameWare Mini Remote Control Server - System
CVE-2003-1030localwindows13 Aug 2003
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RISK
open
Exploit-DBVexDay Proof
Oracle XDB FTP Service - UNLOCK Buffer Overflow
CVE-2003-0727remotewindows13 Aug 2003
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open
Exploit-DBVexDay Proof
PHPOutSourcing Zorum 3.x - Cross-Site Scripting
CVE-2003-1088webappsphp11 Aug 2003
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting
CVE-2003-0736webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting
CVE-2003-0736webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting
CVE-2003-0736webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
PHPOutsourcing Zorum 3.4 - Full Path Disclosure
CVE-2003-1089webappsphp11 Aug 2003
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names,
23RISK
open
Exploit-DBVexDay Proof
WU-FTPD 2.6.2 - Remote Command Execution
CVE-2003-0466remotelinux11 Aug 2003
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - DCOM RPC Interface Buffer Overrun
CVE-2003-0352remotewindows11 Aug 2003
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting
CVE-2003-0736webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection
CVE-2003-0735webappsphp11 Aug 2003
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Cisco IOS 12.x/11.x - HTTP Remote Integer Overflow
CVE-2003-0647remotehardware10 Aug 2003
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
CVE-2004-2131localunix08 Aug 2003
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting
CVE-2004-1957webappsphp08 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
CVE-2004-2131localunix08 Aug 2003
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'RPC DCOM' Remote (Universal)
CVE-2003-0605remotewindows07 Aug 2003
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RISK
open
Exploit-DBVexDay Proof
man-db 2.4.1 - 'open_cat_stream()' Local uid=man
CVE-2003-0645locallinux06 Aug 2003
man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when run
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0 - 'register.php' HTML Injection
CVE-2003-1031webappsphp06 Aug 2003
Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
WU-FTPD 2.6.0/2.6.1/2.6.2 - 'realpath()' Off-by-One Buffer Overflow
CVE-2003-0466remoteunix06 Aug 2003
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open
Exploit-DBVexDay Proof
IBM DB2 - Shared Library Injection
CVE-2003-1052localunix05 Aug 2003
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid
23RISK
open
Exploit-DBVexDay Proof
IBM DB2 db2job - File Overwrite
CVE-2003-0898localunix05 Aug 2003
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and g
23RISK
open
Exploit-DBVexDay Proof
Postfix 1.1.x - Denial of Service (2)
CVE-2003-0540doslinux04 Aug 2003
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISK
open
Exploit-DBVexDay Proof
Postfix 1.1.x - Denial of Service (1)
CVE-2003-0540doslinux04 Aug 2003
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1
28RISK
open
Exploit-DBVexDay Proof
WU-FTPD 2.6.2 - Off-by-One Remote Command Execution
CVE-2003-0466remotelinux03 Aug 2003
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open
previouspage 725 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.