Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
MarmaraWeb E-Commerce - Remote File Inclusion
CVE-2005-4287webappsphp15 Dec 2005
PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the
23RISK
open
Exploit-DBVexDay Proof
AltantForum 4.0.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4298webappscgi15 Dec 2005
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
ZixForum 1.12 - 'forum.asp' Multiple SQL Injections
CVE-2005-4334webappsasp15 Dec 2005
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID para
23RISK
open
Exploit-DBVexDay Proof
Soft4e ECW-Cart 2.0.3 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4290webappscgi15 Dec 2005
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
TML 0.5 - 'index.php?id' SQL Injection
CVE-2005-4416webappsphp15 Dec 2005
SQL injection vulnerability in index.php in TML CMS 0.5 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'subscribers.tracking.edit.php?subtrackingid' SQL Injection
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
WikkaWiki 1.1.6 - 'TextSearch.php' Cross-Site Scripting
CVE-2005-4255webappsphp14 Dec 2005
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Macromedia Flash Media Server 2 - Remote Denial of Service
CVE-2005-4216doswindows14 Dec 2005
The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'customer.tickets.view.php' Multiple SQL Injections
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
Jamit Job Board 2.4.1 - 'index.php' SQL Injection
CVE-2005-4232webappsphp14 Dec 2005
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
Scientific Atlanta DPX2100 Cable Modem - LanD Packet Denial of Service
CVE-2005-4275doshardware14 Dec 2005
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP pac
23RISK
open
Exploit-DBVexDay Proof
AppServ Open Project 2.5.3 - Remote Denial of Service
CVE-2005-4296doswindows14 Dec 2005
AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.
23RISK
open
Exploit-DBVexDay Proof
Limbo 1.0.4.2 - '_SERVER[REMOTE_ADDR]' Remote Command Execution
CVE-2005-4318webappsphp14 Dec 2005
SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote atta
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'popups.edit.php?popupid' SQL Injection
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
PHP Web Scripts Ad Manager Pro 2.0 - 'Advertiser_statistic.php' SQL Injection
CVE-2005-4233webappsphp14 Dec 2005
SQL injection vulnerability in advertiser_statistic.php in Ad Manager Pro 2.0 and earlier allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'design.php?delete' SQL Injection
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
News Module for Envolution - 'modules.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4262webappsphp14 Dec 2005
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
ASPBB 0.4 - 'topic.asp?TID' SQL Injection
CVE-2005-4259webappsasp14 Dec 2005
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
ASPBB 0.4 - 'profile.asp?PROFILE_ID' SQL Injection
CVE-2005-4259webappsasp14 Dec 2005
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
ASPBB 0.4 - 'forum.asp?FORUM_ID' SQL Injection
CVE-2005-4259webappsasp14 Dec 2005
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'sales.view.php?customerid' SQL Injection
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
DreamLevels Dream Poll 3.0 - 'View_Results.php' SQL Injection
CVE-2005-4254webappsphp14 Dec 2005
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Netref 3.0 - 'index.php' SQL Injection
CVE-2005-4198webappsphp14 Dec 2005
SQL injection vulnerability in index.php in Netref 3.0 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
QuickPayPro 3.1 - 'tracking.details.php?trackingid' SQL Injection
CVE-2005-4243webappsphp14 Dec 2005
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
News Module for Envolution - 'modules.php' Multiple SQL Injections
CVE-2005-4263webappsphp14 Dec 2005
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Westell Versalink 327W - LanD Packet Denial of Service
CVE-2005-4276doshardware14 Dec 2005
Westell Versalink 327W allows remote attackers to cause a denial of service (device crash) via an IP packet with the sam
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.x - Content Filtering Bypass
CVE-2005-4260webappsphp14 Dec 2005
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site
23RISK
open
Exploit-DBVexDay Proof
Limbo CMS 1.0.4.2 - 'option' Traversal Arbitrary File Access
CVE-2005-4319webappsphp14 Dec 2005
Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbi
23RISK
open
Exploit-DBVexDay Proof
ASP-DEV XM Forum - 'forum.asp' Cross-Site Scripting
CVE-2005-4256webappsasp14 Dec 2005
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
Limbo CMS 1.0.4.2 - 'index.php?_SERVER[REMOTE_ADDR]' Cross-Site Scripting
CVE-2005-4317webappsphp14 Dec 2005
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modificat
23RISK
open
previouspage 455 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.