Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,190cataloged exploits
37,765CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Crob FTP Server 3.5.1 - Remote Information Disclosure
CVE-2004-2309remotewindows02 Feb 2004
Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multipl
23RISK
open
Exploit-DBVexDay Proof
Leif M. Wright Web Blog 1.1 - Remote Command Execution
CVE-2004-2347webappscgi31 Jan 2004
blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metach
23RISK
open
Exploit-DBVexDay Proof
Aprox Portal 3.0 - File Disclosure
CVE-2004-0237webappsphp31 Jan 2004
Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a
23RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTPd Server 4.x - 'site chmod' Remote Buffer Overflow
CVE-2004-2111remotewindows30 Jan 2004
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISK
open
Exploit-DBVexDay Proof
JBrowser 1.0/2.x - Unauthorized Admin Access
CVE-2007-1156webappsphp30 Jan 2004
JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct re
23RISK
open
Exploit-DBVexDay Proof
Laurent Adda Les Commentaires 2.0 - PHP Script 'derniers_commentaires.php' Remote File Inclusion
CVE-2004-0246webappsphp30 Jan 2004
Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admi
23RISK
open
Exploit-DBVexDay Proof
JBrowser 1.0/2.x - 'browser.php' Directory Traversal
CVE-2004-2750webappsphp30 Jan 2004
Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary f
23RISK
open
Exploit-DBVexDay Proof
Laurent Adda Les Commentaires 2.0 - PHP Script 'admin.php' Remote File Inclusion
CVE-2004-0246webappsphp30 Jan 2004
Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admi
23RISK
open
Exploit-DBVexDay Proof
Laurent Adda Les Commentaires 2.0 - PHP Script 'fonctions.lib.php' Remote File Inclusion
CVE-2004-0246webappsphp30 Jan 2004
Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admi
23RISK
open
Exploit-DBVexDay Proof
PHPGedView 2.x - '[GED_File]_conf.php' Remote File Inclusion
CVE-2004-0128webappsphp30 Jan 2004
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remo
23RISK
open
Exploit-DBVexDay Proof
PJ CGI Neo Review - Directory Traversal
CVE-2004-2132webappscgi29 Jan 2004
Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary fil
23RISK
open
Exploit-DBVexDay Proof
OracleAS TopLink Mapping Workbench - Weak Encryption Algorithm
CVE-2004-2134localmultiple28 Jan 2004
Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the
23RISK
open
Exploit-DBVexDay Proof
Loom Software SurfNow 1.x/2.x - GET Remote Denial of Service
CVE-2004-2129doswindows28 Jan 2004
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibl
23RISK
open
Exploit-DBVexDay Proof
BRS Webweaver 1.0.7 - 'ISAPISkeleton.dll' Cross-Site Scripting
CVE-2004-2128remotewindows28 Jan 2004
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as ot
23RISK
open
Exploit-DBVexDay Proof
phpGroupWare 0.9.14 - 'Tables_Update.Inc.php' Remote File Inclusion
CVE-2004-2573webappsphp27 Jan 2004
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote at
23RISK
open
Exploit-DBVexDay Proof
phpGroupWare 0.9.x - 'index.php' HTML Injection
CVE-2004-2574webappsphp27 Jan 2004
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTPd Server 3.x/4.x - 'SITE CHMOD' Remote Overflow
CVE-2004-2111remotewindows27 Jan 2004
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISK
open
Exploit-DBVexDay Proof
Xoops 2.0.x - 'viewtopic.php' Cross-Site Scripting
CVE-2004-2756webappsphp26 Jan 2004
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
herberlin bremsserver 1.2.4/3.0 - Directory Traversal
CVE-2004-2112remotewindows26 Jan 2004
Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot
23RISK
open
Exploit-DBVexDay Proof
Cherokee 0.1.x/0.2.x/0.4.x - Error Page Cross-Site Scripting
CVE-2004-2171remotesolaris26 Jan 2004
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
InternetNow ProxyNow 2.6/2.75 - Multiple Stack / Heap Overflow Vulnerabilities
CVE-2004-2114remotewindows26 Jan 2004
Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary co
23RISK
open
Exploit-DBVexDay Proof
IBM Net.Data 7.0/7.2 - db2www Error Message Cross-Site Scripting
CVE-2004-1442remotemultiple26 Jan 2004
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Gallery 1.3.x/1.4 - Remote Global Variable Injection
CVE-2004-2124webappsphp26 Jan 2004
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POS
23RISK
open
Exploit-DBVexDay Proof
Herberlin BremsServer 1.2.4 - Cross-Site Scripting
CVE-2004-2113remotemultiple26 Jan 2004
Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or
23RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTPd Server 3/4 - MDTM Command Stack Overflow (2)
CVE-2004-2111remotewindows25 Jan 2004
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTPd Server 3/4 - MDTM Command Stack Overflow (1)
CVE-2004-2111remotewindows24 Jan 2004
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISK
open
Exploit-DBVexDay Proof
borland Web server for corel paradox 1.0 b3 - Directory Traversal
CVE-2004-2121remotewindows24 Jan 2004
Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to rea
23RISK
open
Exploit-DBVexDay Proof
tinyserver 1.1 - Directory Traversal
CVE-2004-2116remotewindows24 Jan 2004
Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .
23RISK
open
Exploit-DBVexDay Proof
TinyServer 1.1 - Denial of Service
CVE-2004-2117doswindows24 Jan 2004
Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a G
23RISK
open
Exploit-DBVexDay Proof
Oracle HTTP Server 8.1.7/9.0.1/9.2 - isqlplus Cross-Site Scripting
CVE-2004-2115remotemultiple24 Jan 2004
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker
35RISK
open
previouspage 536 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.