Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
NOCC 0.9.x - Webmail Script Injection
CVE-2002-2343webappsphp14 May 2002
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
Critical Path InJoin Directory Server 4.0 - Cross-Site Scripting
CVE-2002-0787remotemultiple10 May 2002
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 all
23RISK
open
Exploit-DBVexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
CVE-2002-0379remotelinux10 May 2002
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RISK
open
Exploit-DBVexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
CVE-2002-0379remotelinux10 May 2002
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RISK
open
Exploit-DBVexDay Proof
Critical Path InJoin Directory Server 4.0 - File Disclosure
CVE-2002-0786remotemultiple10 May 2002
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators
23RISK
open
Exploit-DBVexDay Proof
Cisco ATA-186 - HTTP Device Configuration Disclosure
CVE-2002-0769remotehardware09 May 2002
The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass a
23RISK
open
Exploit-DBVexDay Proof
ISC DHCPD 2.0/3.0.1 - NSUPDATE Remote Format String
CVE-2002-0702remotebsd08 May 2002
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0
35RISK
open
Exploit-DBVexDay Proof
WorldClient 5.0.x - Arbitrary File Deletion
CVE-2002-1741remotewindows07 May 2002
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier a
23RISK
open
Exploit-DBVexDay Proof
MDaemon WorldClient 5.0.x - Folder Creation Buffer Overflow
CVE-2002-1740remotewindows07 May 2002
Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users t
23RISK
open
Exploit-DBVexDay Proof
B2 0.6 - 'b2edit.showposts.php?b2inc' Remote File Inclusion
CVE-2002-0734webappsphp06 May 2002
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, wh
23RISK
open
Exploit-DBVexDay Proof
askSam 4.0 Web Publisher - Cross-Site Scripting
CVE-2002-1727webappscgi05 May 2002
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows re
23RISK
open
Exploit-DBVexDay Proof
Outfront Spooky 2.x - Login SQL Query Manipulation Password
CVE-2002-1720webappsasp02 May 2002
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain pr
23RISK
open
Exploit-DBVexDay Proof
SSH (x2) - Remote Command Execution
CVE-2001-0144remotemultiple01 May 2002
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server
35RISK
open
Exploit-DBVexDay Proof
MyGuestbook 1.0 - Script Injection
CVE-2002-0732webappscgi30 Apr 2002
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML
23RISK
open
Exploit-DBVexDay Proof
BEA Systems WebLogic Server and Express 7.0 - Null Character Denial of Service
CVE-2002-0106doswindows30 Apr 2002
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP fi
23RISK
open
Exploit-DBVexDay Proof
Blahz-DNS 0.2 - Direct Script Call Authentication Bypass
CVE-2002-0599webappsphp28 Apr 2002
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesti
28RISK
open
Exploit-DBVexDay Proof
DNSTools 2.0 - Authentication Bypass
CVE-2002-0613webappsphp28 Apr 2002
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by
28RISK
open
Exploit-DBVexDay Proof
ACME Labs thttpd 2.20 - Cross-Site Scripting
CVE-2002-0733remotelinux25 Apr 2002
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a
23RISK
open
Exploit-DBVexDay Proof
PHProjekt 2.x/3.x - Authentication Bypass
CVE-2002-1757webappsphp25 Apr 2002
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass a
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (4)
CVE-2002-0079remotewindows24 Apr 2002
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISK
open
Exploit-DBVexDay Proof
CGIScript.net - csMailto Hidden Form Field Remote Command Execution
CVE-2002-0749remotecgi23 Apr 2002
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-at
28RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.x / FreeBSD 4.x / OpenBSD 2.x / Solaris 2.5/2.6/7.0/8 - 'exec C Library' Standard I/O File Descriptor Closure
CVE-2002-0572localbsd23 Apr 2002
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from res
23RISK
open
Exploit-DBVexDay Proof
Matu FTP 1.74 - Client Buffer Overflow
CVE-2002-0608remotewindows23 Apr 2002
Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.
23RISK
open
Exploit-DBVexDay Proof
GNU Screen 3.9.x Braille Module - Local Buffer Overflow
CVE-2002-1602localunix23 Apr 2002
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute
23RISK
open
Exploit-DBVexDay Proof
Apache Tomcat 4.0/4.1 - Servlet Full Path Disclosure
CVE-2002-2006remoteunix23 Apr 2002
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the in
35RISK
open
Exploit-DBVexDay Proof
SLRNPull 0.9.6 - Spool Directory Command Line Parameter Buffer Overflow
CVE-2002-0740localunix22 Apr 2002
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RISK
open
Exploit-DBVexDay Proof
psyBNC 2.3 - Oversized Passwords Denial of Service
CVE-2002-0741dosunix22 Apr 2002
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a P
23RISK
open
Exploit-DBVexDay Proof
Philip Chinery's Guestbook 1.1 - Script Injection
CVE-2002-0730webappscgi21 Apr 2002
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
vqServer 1.9.x - CGI Demo Program Script Injection
CVE-2002-0731webappscgi21 Apr 2002
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary sc
23RISK
open
Exploit-DBVexDay Proof
Jon Howell Faq-O-Matic 2.7 - Cross-Site Scripting
CVE-2002-2011webappscgi20 Apr 2002
Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote a
23RISK
open
previouspage 756 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.