Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
CVE-2003-0130remotelinux19 Mar 2003
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly esca
28RISK
open
Exploit-DBVexDay Proof
WFChat 1.0 - Information Disclosure
CVE-2003-1540remotemultiple19 Mar 2003
WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open
Exploit-DBVexDay Proof
Mambo Site Server 4.0.10 - 'index.php' Cross-Site Scripting
CVE-2003-1203webappsphp18 Mar 2003
Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute sc
23RISK
open
Exploit-DBVexDay Proof
SIPS 0.2.2 - User Information Disclosure
CVE-2003-1553remotemultiple18 Mar 2003
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insuff
23RISK
open
Exploit-DBVexDay Proof
MyABraCaDaWeb 1.0 - Full Path Disclosure
CVE-2003-1548webappsphp17 Mar 2003
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (4)
CVE-2003-0109remotewindows17 Mar 2003
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RISK
open
Exploit-DBVexDay Proof
Ximian Evolution 1.x - UUEncoding Denial of Service
CVE-2003-0128doslinux17 Mar 2003
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attack
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.2.x/2.4.x - Privileged Process Hijacking Privilege Escalation (1)
CVE-2003-0127locallinux17 Mar 2003
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RISK
open
Exploit-DBVexDay Proof
Ximian Evolution 1.x - UUEncoding Parsing Memory Corruption
CVE-2003-0129remotelinux17 Mar 2003
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumpt
28RISK
open
Exploit-DBVexDay Proof
Samba 2.2.x - CIFS/9000 Server A.01.x Packet Assembling Buffer Overflow
CVE-2003-0085remoteunix15 Mar 2003
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-
45RISK
open
Exploit-DBVexDay Proof
Man Program 1.5 - Unsafe Return Value Command Execution
CVE-2003-0124locallinux11 Mar 2003
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes t
23RISK
open
Exploit-DBVexDay Proof
Multitech RouteFinder 550 - Remote Memory Corruption
CVE-2003-0125dosmultiple11 Mar 2003
Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a de
28RISK
open
Exploit-DBVexDay Proof
Qpopper 4.0.x - Remote Memory Corruption
CVE-2003-0143remotelinux10 Mar 2003
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprint
23RISK
open
Exploit-DBVexDay Proof
MySQL 3.23.x - 'mysqld' Local Privilege Escalation
CVE-2003-0150locallinux08 Mar 2003
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SEL
35RISK
open
Exploit-DBVexDay Proof
Clearswift MAILsweeper 4.x - MIME Attachment Filter Bypass
CVE-2003-0121remotewindows07 Mar 2003
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specif
23RISK
open
Exploit-DBVexDay Proof
File 3.x - Utility Local Memory Allocation
CVE-2003-1092locallinux06 Mar 2003
Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.
23RISK
open
Exploit-DBVexDay Proof
File 3.x - Local Stack Overflow Code Execution (1)
CVE-2003-0102localunix04 Mar 2003
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RISK
open
Exploit-DBVexDay Proof
File 3.x - Local Stack Overflow Code Execution (2)
CVE-2003-0102localunix04 Mar 2003
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RISK
open
Exploit-DBVexDay Proof
HP JetDirect Printer - SNMP JetAdmin Device Password Disclosure
CVE-2002-1048remotehardware03 Mar 2003
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet servic
28RISK
open
Exploit-DBVexDay Proof
Sendmail 8.12.x - Header Processing Buffer Overflow (1)
CVE-2002-1337remoteunix02 Mar 2003
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre
45RISK
open
Exploit-DBVexDay Proof
Sendmail 8.12.x - Header Processing Buffer Overflow (2)
CVE-2002-1337remoteunix02 Mar 2003
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre
45RISK
open
Exploit-DBVexDay Proof
TCPDump 3.x - Malformed ISAKMP Packet Denial of Service
CVE-2003-0108doslinux01 Mar 2003
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via
28RISK
open
Exploit-DBVexDay Proof
Axis Communications HTTP Server 2.x - Messages Information Disclosure
CVE-2003-1386remotemultiple28 Feb 2003
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to
23RISK
open
Exploit-DBVexDay Proof
Apple QuickTime/Darwin Streaming Server 4.1.x - 'parse_xml.cgi' File Disclosure
CVE-2003-1414remotecgi28 Feb 2003
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Serv
23RISK
open
Exploit-DBVexDay Proof
Invision Board 1.1.1 - 'ipchat.php' Remote File Inclusion
CVE-2003-1385webappsphp27 Feb 2003
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is e
23RISK
open
Exploit-DBVexDay Proof
Electronic Arts Battlefield 1942 1.2/1.3 - Remote Administration Authentication Buffer Overflow
CVE-2003-1355doswindows26 Feb 2003
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial o
23RISK
open
Exploit-DBVexDay Proof
AMX Mod 0.9.2 - Remote 'amx_say' Format String
CVE-2003-1381remotelinux26 Feb 2003
Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/ME - Help and Support Center Buffer Overflow
CVE-2003-0009remotewindows26 Feb 2003
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to
28RISK
open
Exploit-DBVexDay Proof
CuteNews 0.88 - 'comments.php' Remote File Inclusion
CVE-2003-1240webappsphp25 Feb 2003
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL
23RISK
open
Exploit-DBVexDay Proof
CuteNews 0.88 - 'search.php' Remote File Inclusion
CVE-2003-1240webappsphp25 Feb 2003
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL
23RISK
open
previouspage 735 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.