Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Sendmail 8.9.x/8.10.x/8.11.x/8.12.x - File Locking Denial of Service (2)
CVE-2002-1827doslinux24 May 2002
Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1)
23RISK
open
Exploit-DBVexDay Proof
OpenBB 1.0 - Unauthorized Moderator Access
CVE-2002-1830webappsphp24 May 2002
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via
23RISK
open
Exploit-DBVexDay Proof
LocalWEB2000 2.1.0 Standard - File Disclosure
CVE-2002-0897remotewindows24 May 2002
LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that
23RISK
open
Exploit-DBVexDay Proof
OpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection
CVE-2002-0330webappsphp24 May 2002
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
ViewCVS 0.9.2 - Cross-Site Scripting
CVE-2002-0771webappscgi24 May 2002
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal c
23RISK
open
Exploit-DBVexDay Proof
Microsoft MSN Messenger 1 < 4 - Malformed Invite Request Denial of Service
CVE-2002-1831doswindows24 May 2002
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invi
28RISK
open
Exploit-DBVexDay Proof
OpenBB 1.0.0 RC3 - BBCode Cross Agent HTML Injection
CVE-2002-1829webappsphp24 May 2002
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attack
23RISK
open
Exploit-DBVexDay Proof
Cisco CBOS 2.x - Broadband Operating System TCP/IP Stack Denial of Service
CVE-2002-0886doshardware23 May 2002
Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memor
23RISK
open
Exploit-DBVexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 - File Disclosure
CVE-2002-0893remotewindows22 May 2002
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files vi
23RISK
open
Exploit-DBVexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 - Full Path Disclosure
CVE-2002-0892remotewindows22 May 2002
The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web r
23RISK
open
Exploit-DBVexDay Proof
NewAtlanta ServletExec/ISAPI 4.1 JSPServlet - Denial of Service
CVE-2002-0894doswindows22 May 2002
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a lo
23RISK
open
Exploit-DBVexDay Proof
Matu FTP Server 1.13 - Remote Buffer Overflow
CVE-2002-0895remotewindows22 May 2002
Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execu
23RISK
open
Exploit-DBVexDay Proof
Cisco IOS 11.x/12.0 - ICMP Redirect Denial of Service
CVE-2002-2315doshardware21 May 2002
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a deni
23RISK
open
Exploit-DBVexDay Proof
Youngzsoft CMailServer 3.30/4.0 - Remote Buffer Overflow (2)
CVE-2002-0799remotewindows21 May 2002
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argumen
28RISK
open
Exploit-DBVexDay Proof
Youngzsoft CMailServer 3.30/4.0 - Remote Buffer Overflow (1)
CVE-2002-0799remotewindows20 May 2002
Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argumen
28RISK
open
Exploit-DBVexDay Proof
GNU Mailman 2.0.x - Admin Login Cross-Site Scripting
CVE-2002-0388webappscgi20 May 2002
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin
23RISK
open
Exploit-DBVexDay Proof
Hosting Controller 1.x - 'Browse.asp' File Disclosure
CVE-2002-0775webappsasp19 May 2002
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname
23RISK
open
Exploit-DBVexDay Proof
psyBNC 2.3 - Denial of Service
CVE-2002-0741dosmultiple19 May 2002
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a P
23RISK
open
Exploit-DBVexDay Proof
Phorum 3.3.2a - Remote Command Execution
CVE-2002-0764webappsphp17 May 2002
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php
35RISK
open
Exploit-DBVexDay Proof
Hosting Controller 1.x - DSNManager Directory Traversal
CVE-2002-0772webappsasp17 May 2002
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary fil
23RISK
open
Exploit-DBVexDay Proof
Hosting Controller 1.4 - Import Root Directory Command Execution
CVE-2002-0773webappsasp17 May 2002
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a d
23RISK
open
Exploit-DBVexDay Proof
Grsecurity Kernel Patch 1.9.4 (Linux Kernel) - Memory Protection
CVE-2002-1826locallinux17 May 2002
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly ma
23RISK
open
Exploit-DBVexDay Proof
SonicWALL SOHO3 6.3 - Content Blocking Script Injection
CVE-2002-2341remotemultiple17 May 2002
Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
Cisco IDS Device Manager 3.1.1 - Arbitrary File Read Access
CVE-2002-0908remotehardware17 May 2002
Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
CVE-2002-0193remotewindows15 May 2002
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposit
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
CVE-2002-0192remotewindows15 May 2002
20RISK
open
Exploit-DBVexDay Proof
id Software Quake II Server 3.20/3.21 - Remote Information Disclosure
CVE-2002-0770remotemultiple15 May 2002
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory li
23RISK
open
Exploit-DBVexDay Proof
Opera 5.12/6.0 - Frame Location Same Origin Policy Circumvention
CVE-2002-0783remotewindows15 May 2002
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites
23RISK
open
Exploit-DBVexDay Proof
Squid 2.4.1 - Remote Buffer Overflow
CVE-2002-0163remotelinux14 May 2002
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows
28RISK
open
Exploit-DBVexDay Proof
NOCC 0.9.x - Webmail Script Injection
CVE-2002-2343webappsphp14 May 2002
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web scrip
23RISK
open
previouspage 755 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.