Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Apache 1.3.x mod_include - Local Buffer Overflow
CVE-2004-0940locallinux18 Oct 2004
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISK
open
Exploit-DBVexDay Proof
best software SalesLogix 2000.0 - Multiple Vulnerabilities
CVE-2004-1612remotewindows18 Oct 2004
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open
Exploit-DBVexDay Proof
SLX Server 6.1 - Arbitrary File Creation
CVE-2004-1612remotewindows18 Oct 2004
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISK
open
Exploit-DBVexDay Proof
IBM Lotus Domino 6.x - Cross-Site Scripting / HTML Injection
CVE-2004-1621webappsunix18 Oct 2004
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Do
23RISK
open
Exploit-DBVexDay Proof
Monit 4.2 - Basic Authentication Remote Code Execution
CVE-2004-1898remotelinux17 Oct 2004
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute
28RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.2.10 - Remote Users Enumeration
CVE-2004-1602remotelinux17 Oct 2004
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NNTP Service (XPAT) - Denial of Service (MS04-036)
CVE-2004-0574doswindows16 Oct 2004
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser
35RISK
open
Exploit-DBVexDay Proof
CoolPHP 1.0 - Multiple Remote Input Validation Vulnerabilities
CVE-2004-1601webappsphp16 Oct 2004
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files a
23RISK
open
Exploit-DBVexDay Proof
YahooPOPs 1.6 - SMTP Port Buffer Overflow
CVE-2004-1558remotewindows15 Oct 2004
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISK
open
Exploit-DBVexDay Proof
Yak! Chat Client 2.x - FTP Server Directory Traversal
CVE-2004-2184doswindows15 Oct 2004
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write ar
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP - Weak Default Configuration
CVE-2004-2176localwindows13 Oct 2004
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which
23RISK
open
Exploit-DBVexDay Proof
ocPortal 1.0.3 - Remote File Inclusion
CVE-2004-1592webappsphp13 Oct 2004
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
3Com 3CRADSL72 ADSL Wireless Router - Information Disclosure / Authentication Bypass
CVE-2004-1596remotehardware13 Oct 2004
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as
23RISK
open
Exploit-DBVexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (2)
CVE-2004-1561remotewindows12 Oct 2004
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
Exploit-DBVexDay Proof
DUclassmate 1.x - 'account.asp?MM-recordId' Arbitrary Password Modification
CVE-2004-2198webappsasp11 Oct 2004
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by
23RISK
open
Exploit-DBVexDay Proof
DUforum 3.x - Login Form 'Password' SQL Injection
CVE-2004-2201webappsasp11 Oct 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
DUforum 3.x - 'messages.asp?FOR_ID' SQL Injection
CVE-2004-2201webappsasp11 Oct 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
DUforum 3.x - 'messageDetail.asp?MSG_ID' SQL Injection
CVE-2004-2201webappsasp11 Oct 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
DUclassified 4.x - 'adDetail.asp' Multiple SQL Injections
CVE-2004-2202webappsasp11 Oct 2004
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authenti
23RISK
open
Exploit-DBVexDay Proof
Monolith Games - Local Buffer Overflow (PoC)
CVE-2004-1587doswindows10 Oct 2004
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 1.2 - HTTP Splitting
CVE-2004-1584webappsphp10 Oct 2004
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting
28RISK
open
Exploit-DBVexDay Proof
MySQL 3.x/4.x - ALTER TABLE/RENAME Forces Old Permission Checks
CVE-2004-0835remotelinux08 Oct 2004
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o
28RISK
open
Exploit-DBVexDay Proof
DCP-Portal 3.7/4.x/5.x - 'news.php?cid' Cross-Site Scripting
CVE-2004-2511webappsphp06 Oct 2004
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
DCP-Portal 3.7/4.x/5.x - 'calendar.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2511webappsphp06 Oct 2004
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (1)
CVE-2004-1561remotewindows06 Oct 2004
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
Exploit-DBVexDay Proof
Microsoft ASP.NET 1.x - URI Canonicalization Unauthorized Web Access
CVE-2004-0847webappsasp06 Oct 2004
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .asp
45RISK
open
Exploit-DBVexDay Proof
DCP-Portal 3.7/4.x/5.x - 'calendar.php' HTTP Response Splitting
CVE-2004-2512webappsphp06 Oct 2004
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP res
23RISK
open
Exploit-DBVexDay Proof
DCP-Portal 3.7/4.x/5.x - 'announcement.php?cid' Cross-Site Scripting
CVE-2004-2511webappsphp06 Oct 2004
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
IPSwitch WhatsUp Gold 8.03 - Remote Buffer Overflow
CVE-2004-0798remotewindows04 Oct 2004
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open
Exploit-DBVexDay Proof
W-Agora 4.1.6a - 'login.php?loginuser' Cross-Site Scripting
CVE-2004-1563webappsphp30 Sep 2004
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web sc
23RISK
open
previouspage 512 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.