Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,258cataloged exploits
36,019CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
ISC INN 2.0/2.1/2.2.x - Multiple Local Format String Vulnerabilities
CVE-2002-0525locallinux11 Apr 2002
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - HTTP Error Page Cross-Site Scripting
CVE-2002-0148remotewindows10 Apr 2002
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to exec
35RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (1)
CVE-2002-0079remotewindows10 Apr 2002
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (3)
CVE-2002-0079remotewindows10 Apr 2002
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISK
open
Exploit-DBVexDay Proof
Abyss Web Server 1.0 - File Disclosure
CVE-2002-0543remotewindows07 Apr 2002
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read
23RISK
open
Exploit-DBVexDay Proof
Abyss Web Server 1.0 - File Disclosure
CVE-2002-0544remotewindows07 Apr 2002
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.co
23RISK
open
Exploit-DBVexDay Proof
phpGroupWare 0.9.13 - Debian Package Configuration
CVE-2002-0536remotelinux03 Apr 2002
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to com
23RISK
open
Exploit-DBVexDay Proof
Sun Solaris 2.6/7.0/8 - XSun Color Database File Heap Overflow
CVE-2002-0158localsolaris02 Apr 2002
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color databa
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - Cascading Style Sheet File Disclosure (MS02-023)
CVE-2002-0191remotewindows02 Apr 2002
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" chara
28RISK
open
Exploit-DBVexDay Proof
Oracle 8i - TNS Listener Local Command Parameter Buffer Overflow
CVE-2002-1767locallinux01 Apr 2002
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.703 - caselist Arbitrary Module Include
CVE-2002-2015webappsphp28 Mar 2002
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and po
23RISK
open
Exploit-DBVexDay Proof
SquirrelMail 1.2.x - Theme Remote Command Execution
CVE-2002-0516webappsphp28 Mar 2002
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the TH
28RISK
open
Exploit-DBVexDay Proof
LogWatch 2.1.1/2.5 - Insecure Temporary Directory Creation
CVE-2002-0162locallinux27 Mar 2002
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary director
23RISK
open
Exploit-DBVexDay Proof
Citrix NFuse 1.51/1.6 - Cross-Site Scripting
CVE-2002-0504remotejsp27 Mar 2002
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method,
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.2.x/2.3/2.4.x - 'd_path()' Path Truncation
CVE-2002-0499locallinux26 Mar 2002
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generat
23RISK
open
Exploit-DBVexDay Proof
CSSearch 2.3 - Remote Command Execution
CVE-2002-0495remotecgi26 Mar 2002
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup comman
28RISK
open
Exploit-DBVexDay Proof
DCShop Beta 1.0 - Form Manipulation
CVE-2002-0492webappscgi25 Mar 2002
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the data
23RISK
open
Exploit-DBVexDay Proof
Progress Database 9.1 - sqlcpp Local Buffer Overflow
CVE-2001-1127localmultiple22 Mar 2002
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RISK
open
Exploit-DBVexDay Proof
WorkforceROI Xpede 4.1/7.0 - Weak Password Encryption
CVE-2002-0486localwindows22 Mar 2002
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users
23RISK
open
Exploit-DBVexDay Proof
Apache Win32 1.3.x/2.0.x - Batch File Remote Command Execution
CVE-2002-0061remotewindows21 Mar 2002
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via
35RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 5.x - Error Message Web Root Disclosure
CVE-2002-0483webappsphp21 Mar 2002
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when
23RISK
open
Exploit-DBVexDay Proof
Webmin 0.x - Code Input Validation
CVE-2002-1673locallinux20 Mar 2002
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the inter
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 0.8/0.9.x / Opera 5/6 - JavaScript Interpreter Denial of Service
CVE-2002-0461doswindows19 Mar 2002
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript
28RISK
open
Exploit-DBVexDay Proof
PHP 3.0.x/4.x - Move_Uploaded_File open_basedir Circumvention
CVE-2002-0484localphp17 Mar 2002
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Qualcomm QPopper 4.0.x - Remote Denial of Service
CVE-2002-0454dosunix15 Mar 2002
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumpti
23RISK
open
Exploit-DBVexDay Proof
PHProjekt 3.1 - Remote File Inclusion
CVE-2002-0451webappsphp13 Mar 2002
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0/2000 - Process Handle Local Privilege Escalation
CVE-2002-0367HIGHunder attacklocalwindows13 Mar 2002
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to othe
71RISK
open
Exploit-DBVexDay Proof
Trend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan Bypass
CVE-2002-0440remotemultiple11 Mar 2002
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows
23RISK
open
Exploit-DBVexDay Proof
Solaris 7.0/8 Sunsolve CD - SSCD_SunCourier.pl CGI Script Arbitrary Command Execution
CVE-2002-0436remotecgi11 Mar 2002
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shel
28RISK
open
Exploit-DBVexDay Proof
XTux Server 2001.0 6.01 - Garbage Denial of Service
CVE-2002-0431doslinux09 Mar 2002
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
23RISK
open
previouspage 758 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.