Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit500
Netcat v1.10 NT Stack Buffer Overflow
CVE-2004-131727 Dec 2004
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack
50RISK
open
Metasploit200
SHOUTcast DNAS/win32 1.9.4 File Request Format String Overflow
CVE-2004-137323 Dec 2004
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RISK
open
Metasploit200
CA BrightStor Discovery Service Stack Buffer Overflow
CVE-2005-026020 Dec 2004
Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attac
50RISK
open
Metasploit200
Veritas Backup Exec Name Service Overflow
CVE-2004-117216 Dec 2004
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9
60RISK
open
Metasploit500
MS04-045 Microsoft WINS Service Memory Overwrite
CVE-2004-108014 Dec 2004
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remo
60RISK
open
Metasploit400
Microsoft IIS ISAPI w3who.dll Query String Overflow
CVE-2004-113406 Dec 2004
Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possib
60RISK
open
Metasploit200
Mercury/32 v4.01a IMAP RENAME Buffer Overflow
CVE-2004-121129 Nov 2004
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RISK
open
Metasploit500
WS-FTP Server 5.03 MKD Overflow
CVE-2004-113529 Nov 2004
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service
50RISK
open
Metasploit200
IMail IMAP4D Delete Overflow
CVE-2004-152012 Nov 2004
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RISK
open
Metasploit300
MS06-019 Exchange MODPROP Heap Overflow
CVE-2006-002712 Nov 2004
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages wi
40RISK
open
Metasploit500
Mdaemon 8.0.3 IMAPD CRAM-MD5 Authentication Overflow
CVE-2004-152012 Nov 2004
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RISK
open
Metasploit600
phpBB viewtopic.php Arbitrary Code Execution
CVE-2004-131512 Nov 2004
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RISK
open
Metasploit600
phpBB viewtopic.php Arbitrary Code Execution
CVE-2005-208612 Nov 2004
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute
60RISK
open
Metasploit200
CCProxy Telnet Proxy Ping Overflow
CVE-2004-241611 Nov 2004
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GE
50RISK
open
Metasploit200
Minishare 1.4.1 Buffer Overflow
CVE-2004-227107 Nov 2004
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RISK
open
Metasploit400
TABS MailCarrier v2.51 SMTP EHLO Overflow
CVE-2004-163826 Oct 2004
Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (
50RISK
open
Metasploit300
Ability Server 2.34 STOR Command Stack Buffer Overflow
CVE-2004-162622 Oct 2004
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code v
50RISK
open
Metasploit600
VERITAS NetBackup Remote Command Execution
CVE-2004-138921 Oct 2004
Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1
38RISK
open
Metasploit400
MS04-031 Microsoft NetDDE Service Overflow
CVE-2004-020612 Oct 2004
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and
60RISK
open
Metasploit500
ShixxNOTE 6.net Font Field Overflow
CVE-2004-159504 Oct 2004
Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
50RISK
open
Metasploit600
TWiki Search Function Arbitrary Command Execution
CVE-2004-103701 Oct 2004
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in
50RISK
open
Metasploit500
Icecast Header Overwrite
CVE-2004-156128 Sep 2004
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
Metasploit200
YPOPS 0.6 Buffer Overflow
CVE-2004-155827 Sep 2004
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open
Metasploit300
Motorola WR850G v4.03 Credentials
CVE-2004-155024 Sep 2004
Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an adm
23RISK
open
Metasploit400
Zinf Audio Player 2.2.1 (PLS File) Stack Buffer Overflow
CVE-2004-096424 Sep 2004
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RISK
open
Metasploit500
Ipswitch WhatsUp Gold 8.03 Buffer Overflow
CVE-2004-079825 Aug 2004
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open
Metasploit500
Mercantec SoftCart CGI Overflow
CVE-2004-222119 Aug 2004
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long
50RISK
open
Metasploit500
AOL Instant Messenger goaway Overflow
CVE-2004-063609 Aug 2004
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.
50RISK
open
Metasploit500
Medal of Honor Allied Assault getinfo Stack Buffer Overflow
CVE-2004-073517 Jul 2004
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RISK
open
Metasploit200
WebSTAR FTP Server USER Overflow
CVE-2004-069513 Jul 2004
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISK
open
previouspage 103 / 116next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.