Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Perception LiteServe 2.0 - CGI Source Disclosure
CVE-2002-1986remotemultiple14 Nov 2002
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP requ
23RISK
open
Exploit-DBVexDay Proof
LibHTTPD 1.2 - POST Buffer Overflow
CVE-2002-2400remotelinux13 Nov 2002
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
phpBB Advanced Quick Reply Hack 1.0/1.1 - Remote File Inclusion
CVE-2002-2287webappsphp13 Nov 2002
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows re
23RISK
open
Exploit-DBVexDay Proof
Key Focus KF Web Server 1.0.8 - Directory Traversal
CVE-2002-2403remotewindows13 Nov 2002
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recog
23RISK
open
Exploit-DBVexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (2)
CVE-2002-1549remotelinux12 Nov 2002
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISK
open
Exploit-DBVexDay Proof
ISC BIND 8.3.x - OPT Record Large UDP Denial of Service
CVE-2002-1220doslinux12 Nov 2002
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via
23RISK
open
Exploit-DBVexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (1)
CVE-2002-1549remotelinux12 Nov 2002
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISK
open
Exploit-DBVexDay Proof
Traceroute-nanog 6 - Local Buffer Overflow
CVE-2002-1364locallinux12 Nov 2002
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS
23RISK
open
Exploit-DBVexDay Proof
W3Mail 1.0.6 - File Disclosure
CVE-2002-2399webappscgi12 Nov 2002
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files
23RISK
open
Exploit-DBVexDay Proof
EZ Systems HTTPBench 1.1 - Information Disclosure
CVE-2002-1818webappsphp11 Nov 2002
ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSi
23RISK
open
Exploit-DBVexDay Proof
Hotfoon Dialer 4.0 - Buffer Overflow (PoC)
CVE-2002-2385dosmultiple11 Nov 2002
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly
23RISK
open
Exploit-DBVexDay Proof
Perception LiteServe 2.0.1 - Directory Query String Cross-Site Scripting
CVE-2002-2192remotewindows08 Nov 2002
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Perception LiteServe 2.0.1 - DNS Wildcard Cross-Site Scripting
CVE-2002-2192remotewindows08 Nov 2002
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Zeus Web Server 4.0/4.1 - Admin Interface Cross-Site Scripting
CVE-2002-1785remotecgi08 Nov 2002
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remot
23RISK
open
Exploit-DBVexDay Proof
QNX RTOS 6.2 - Application Packager Non-Explicit Path Execution
CVE-2002-1239locallinux08 Nov 2002
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised
23RISK
open
Exploit-DBVexDay Proof
Simple Web Server 0.5.1 - File Disclosure
CVE-2002-1238remotewindows08 Nov 2002
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via
23RISK
open
Exploit-DBVexDay Proof
Lotus Domino 5.0.8-9 - Non-Existent NSF Database Banner Information Disclosure
CVE-2002-2191remotemultiple07 Nov 2002
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obt
23RISK
open
Exploit-DBVexDay Proof
CuteCast 1.2 - User Credential Disclosure
CVE-2002-2190webappscgi07 Nov 2002
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Pine 4.x - 'From:' Heap Corruption
CVE-2002-1320doslinux07 Nov 2002
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email m
23RISK
open
Exploit-DBVexDay Proof
HP CIFS/9000 Server A.01.05/A.01.06 - Local Buffer Overflow
CVE-2002-0991localhp-ux06 Nov 2002
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RISK
open
Exploit-DBVexDay Proof
QNX 6.1 - 'TimeCreate' Local Denial of Service
CVE-2002-1983dosunix06 Nov 2002
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute a
23RISK
open
Exploit-DBVexDay Proof
Northern Solutions Xeneo Web Server 2.1/2.2 - Denial of Service
CVE-2002-1248doswindows04 Nov 2002
Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause
23RISK
open
Exploit-DBVexDay Proof
Monkey HTTP Server 0.4/0.5 - Invalid POST Denial of Service
CVE-2002-1663doswindows02 Nov 2002
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of se
23RISK
open
Exploit-DBVexDay Proof
Solaris 2.6/7/8 - 'TTYPROMPT in.telnet' Remote Authentication Bypass
CVE-2001-0797remotesolaris02 Nov 2002
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
Linksys BEFSR41 1.4x - 'Gozila.cgi' Denial of Service
CVE-2002-1236doshardware01 Nov 2002
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote att
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 5.6 - 'modules.php' SQL Injection
CVE-2002-1242webappsphp01 Nov 2002
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain pri
23RISK
open
Exploit-DBVexDay Proof
Linksys WAP11 1.3/1.4 / D-Link DI-804 4.68/Dl-704 2.56 b5 - Embedded HTTP Server Denial of Service
CVE-2002-1865doshardware01 Nov 2002
Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (
23RISK
open
Exploit-DBVexDay Proof
Abuse 2.0 - Local Buffer Overflow
CVE-2002-1250locallinux01 Nov 2002
Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argume
23RISK
open
Exploit-DBVexDay Proof
Jason Orcutt Prometheus 3.0/4.0/6.0 - Remote File Inclusion
CVE-2002-1211webappsphp01 Nov 2002
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE
23RISK
open
Exploit-DBVexDay Proof
ION Script 1.4 - Remote File Disclosure
CVE-2002-1559webappscgi01 Nov 2002
Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (d
23RISK
open
previouspage 741 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.