Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,066cataloged exploits
37,668CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
AllMyVisitors 0.x - 'info.inc.php' Arbitrary Code Execution
CVE-2004-0285webappsphp16 Feb 2004
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyG
23RISK
open
Exploit-DBVexDay Proof
YABB SE 1.5 - 'Quote' SQL Injection
CVE-2004-0291webappsphp16 Feb 2004
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords v
23RISK
open
Exploit-DBVexDay Proof
Freeform Interactive Purge 1.4.7/Purge Jihad 2.0.1 Game Client - Remote Buffer Overflow
CVE-2004-0290remotemultiple16 Feb 2004
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information
23RISK
open
Exploit-DBVexDay Proof
ProductCart 1.x/2.x - Weak Cryptography
CVE-2004-2172webappsasp16 Feb 2004
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the
23RISK
open
Exploit-DBVexDay Proof
ACLogic CesarFTP 0.99 - Remote Resource Exhaustion (Denial of Service)
CVE-2004-0298doswindows16 Feb 2004
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.
23RISK
open
Exploit-DBVexDay Proof
RobotFTP Server 1.0/2.0 - 'Username' Buffer Overflow (1)
CVE-2004-0286doswindows16 Feb 2004
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly
23RISK
open
Exploit-DBVexDay Proof
AllMyGuests 0.x - 'info.inc.php' Arbitrary Code Execution
CVE-2004-0285webappsphp16 Feb 2004
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyG
23RISK
open
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - Remote Authentication Bypass
CVE-2005-0408webappsphp15 Feb 2004
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - ASN.1 'LSASS.exe' Remote Denial of Service (MS04-007)
CVE-2003-0818doswindows14 Feb 2004
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RISK
open
Exploit-DBVexDay Proof
KarjaSoft Sami HTTP Server 1.0.4 - GET Buffer Overflow
CVE-2004-0292remotewindows13 Feb 2004
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and pos
23RISK
open
Exploit-DBVexDay Proof
rsync 2.5.7 - Local Stack Overflow / Local Privilege Escalation
CVE-2004-2093locallinux13 Feb 2004
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a de
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - ITS Protocol Zone Bypass (MS04-013)
CVE-2004-0380remotewindows13 Feb 2004
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to
35RISK
open
Exploit-DBVexDay Proof
Sami FTP Server 1.1.3 - Library Crafted GET Remote Denial of Service
CVE-2004-2082doswindows13 Feb 2004
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsyste
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0 - 'search.php' Cross-Site Scripting
CVE-2004-2076webappsphp13 Feb 2004
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Sami FTP Server 1.1.3 - Invalid Command Argument Local Denial of Service
CVE-2004-2081doswindows13 Feb 2004
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
23RISK
open
Exploit-DBVexDay Proof
XFree86 4.x - CopyISOLatin1Lowered Font_Name Buffer Overflow
CVE-2004-0084doslinux12 Feb 2004
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, a
28RISK
open
Exploit-DBVexDay Proof
Crob FTP Server 3.5.2 - Remote Denial of Service
CVE-2004-0282doswindows12 Feb 2004
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disco
23RISK
open
Exploit-DBVexDay Proof
Macallan Mail Solution Macallan Mail Solution 2.8.4.6 (Build 260) - Web Interface Authentication Bypass
CVE-2004-2071webappsphp12 Feb 2004
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat
23RISK
open
Exploit-DBVexDay Proof
VisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File Inclusion
CVE-2004-0132webappsphp11 Feb 2004
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
CVE-2004-0132webappsphp11 Feb 2004
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
BolinTech DreamFTP Server 1.2 (1.02/TryFTP 1.0.0.1) - Remote User Name Format String
CVE-2004-2074remotewindows11 Feb 2004
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISK
open
Exploit-DBVexDay Proof
BosDev BosDates 3.x - SQL Injection
CVE-2004-0275webappsphp11 Feb 2004
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensi
23RISK
open
Exploit-DBVexDay Proof
Monkey HTTP Daemon 0.x - Missing Host Field Denial of Service
CVE-2004-0276doswindows11 Feb 2004
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
Maxwebportal 1.3x - 'down.asp' HTTP_REFERER Cross-Site Scripting
CVE-2004-0271webappsasp10 Feb 2004
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
Maxwebportal 1.3x - Personal Message 'SendTo' Cross-Site Scripting
CVE-2004-0271webappsasp10 Feb 2004
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
EvolutionX - Multiple Remote Buffer Overflow Vulnerabilities
CVE-2004-0268doswindows10 Feb 2004
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1)
23RISK
open
Exploit-DBVexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
CVE-2004-0270doslinux09 Feb 2004
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RISK
open
Exploit-DBVexDay Proof
Nadeo Game Engine - Remote Denial of Service
CVE-2004-2077doslinux09 Feb 2004
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
Red-M Red-Alert 3.1 - Remote Denial of Service
CVE-2004-2078doshardware09 Feb 2004
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss o
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.x 'Reviews' Module - Cross-Site Scripting
CVE-2004-0265webappsphp09 Feb 2004
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitr
23RISK
open
previouspage 534 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.