Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Linux Kernel 2.4 - SUID 'execve()' System Call Race Condition Executable File Read
CVE-2003-0462locallinux26 Jun 2003
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0/2000 - Media Services 'nsiislog.dll' Remote Buffer Overflow
CVE-2003-0349remotewindows25 Jun 2003
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability
60RISK
open
Exploit-DBVexDay Proof
Alt-N WebAdmin 2.0.x - 'USER' Remote Buffer Overflow (2)
CVE-2003-0471remotewindows24 Jun 2003
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISK
open
Exploit-DBVexDay Proof
Gkrellmd 2.1 - Remote Buffer Overflow (1)
CVE-2003-0723dosfreebsd24 Jun 2003
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
23RISK
open
Exploit-DBVexDay Proof
Alt-N WebAdmin 2.0.x - 'USER' Remote Buffer Overflow (1)
CVE-2003-0471remotewindows24 Jun 2003
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISK
open
Exploit-DBVexDay Proof
Gkrellmd 2.1 - Remote Buffer Overflow (2)
CVE-2003-0723remotefreebsd24 Jun 2003
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
23RISK
open
Exploit-DBVexDay Proof
Symantec Security Check RuFSI - ActiveX Control Buffer Overflow
CVE-2003-0470doswindows23 Jun 2003
Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the S
23RISK
open
Exploit-DBVexDay Proof
XMB Forum 1.8 - 'member.php?member' Cross-Site Scripting
CVE-2003-0375webappsphp23 Jun 2003
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
XMB Forum 1.8 - 'buddy.php?action' Cross-Site Scripting
CVE-2003-0483webappsphp23 Jun 2003
Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script
23RISK
open
Exploit-DBVexDay Proof
Yahoo Messenger 5.5 - 'DSR-ducky.c' Remote Overflow
CVE-2002-0031remotewindows23 Jun 2003
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsg
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - HTML Converter HR Align Buffer Overflow
CVE-2003-0469remotewindows23 Jun 2003
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause
35RISK
open
Exploit-DBVexDay Proof
XMB Forum 1.8 - 'member.php' Cross-Site Scripting
CVE-2003-0375webappsphp22 Jun 2003
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
phpBB 2.0.5 - SQL Injection Password Disclosure
CVE-2003-0486webappsphp20 Jun 2003
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashe
23RISK
open
Exploit-DBVexDay Proof
Tutos 1.1 - 'File_Select.php' Cross-Site Scripting
CVE-2003-0481webappsphp20 Jun 2003
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script,
23RISK
open
Exploit-DBVexDay Proof
Tutos 1.1 - File_New Arbitrary File Upload
CVE-2003-0482webappsphp20 Jun 2003
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly acce
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.2.x/2.4.x - '/proc' Filesystem Information Disclosure
CVE-2003-0501locallinux20 Jun 2003
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/sel
23RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.2.9 RC1 - 'mod_sql' SQL Injection
CVE-2003-0500remotelinux19 Jun 2003
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allow
28RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 - Web Mail DO_MAP Module Cross-Site Scripting
CVE-2003-0488webappscgi18 Jun 2003
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 - Web Mail ADD_ACL Module Cross-Site Scripting
CVE-2003-0488webappscgi18 Jun 2003
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 add_acl Module - Overflow
CVE-2003-0487doslinux18 Jun 2003
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 subscribe Module - Overflow
CVE-2003-0487doslinux18 Jun 2003
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 list Module - Overflow
CVE-2003-0487doslinux18 Jun 2003
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISK
open
Exploit-DBVexDay Proof
Kerio MailServer 5.6.3 do_map Module - Overflow
CVE-2003-0487doslinux18 Jun 2003
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - MSXML XML File Parsing Cross-Site Scripting
CVE-2003-0446remotewindows17 Jun 2003
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsof
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - Custom HTTP Error HTML Injection
CVE-2003-0447remotewindows17 Jun 2003
The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in th
28RISK
open
Exploit-DBVexDay Proof
Snitz Forums 2000 3.4.03 - 'search.asp' Cross-Site Scripting
CVE-2003-0492webappsasp16 Jun 2003
Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
Linux PAM 0.77 - Pam_Wheel Module 'getlogin() Username' Spoofing Privilege Escalation
CVE-2003-0388locallinux16 Jun 2003
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof
23RISK
open
Exploit-DBVexDay Proof
LedNews 0.7 Post Script - Code Injection
CVE-2003-0495webappscgi16 Jun 2003
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a new
23RISK
open
Exploit-DBVexDay Proof
PMachine 2.2.1 - '/Lib.Inc.php' Remote File Inclusion / Command Execution
CVE-2003-1086webappsphp15 Jun 2003
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote
23RISK
open
Exploit-DBVexDay Proof
Progress Database 9.1 - Environment Variable Privilege Escalation
CVE-2003-0449locallinux14 Jun 2003
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to g
23RISK
open
previouspage 728 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.