Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,192cataloged exploits
37,765CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (1)
CVE-2003-1174remotewindows03 Nov 2003
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RISK
open
Exploit-DBVexDay Proof
VieNuke VieBoard 2.6 - SQL Injection
CVE-2003-1196webappsasp03 Nov 2003
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Web Wiz Forum 6.34/7.0/7.5 - Unauthorized Private Forum Access
CVE-2003-1176webappsasp03 Nov 2003
post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or wr
23RISK
open
Exploit-DBVexDay Proof
Synthetic Reality SymPoll 1.5 - Cross-Site Scripting
CVE-2003-1175webappsphp03 Nov 2003
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
MPM Guestbook 1.2 - Cross-Site Scripting
CVE-2003-1182webappscgi03 Nov 2003
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or
23RISK
open
Exploit-DBVexDay Proof
IA WebMail Server 3.0/3.1 - GET Buffer Overrun
CVE-2003-1192remotewindows03 Nov 2003
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET
50RISK
open
Exploit-DBVexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (2)
CVE-2003-1174remotewindows03 Nov 2003
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RISK
open
Exploit-DBVexDay Proof
PHPKit 1.6 - 'Include.php' Cross-Site Scripting
CVE-2003-1187webappsphp02 Nov 2003
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
MathoPD 1.x - Remote Buffer Overflow
CVE-2003-1228remotelinux02 Nov 2003
Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions
28RISK
open
Exploit-DBVexDay Proof
DATEV Nutzungskontrolle 2.1/2.2 - Unauthorized Access
CVE-2003-1169localwindows01 Nov 2003
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users
23RISK
open
Exploit-DBVexDay Proof
http commander 4.0 - Directory Traversal
CVE-2003-1166webappsasp01 Nov 2003
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
BRS Webweaver 1.06 - HTTPd 'User-Agent' Remote Denial of Service
CVE-2003-1165dosmultiple01 Nov 2003
Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possi
23RISK
open
Exploit-DBVexDay Proof
MLdonkey 2.5-4 - Cross-Site Scripting
CVE-2003-1164remotemultiple31 Oct 2003
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTM
23RISK
open
Exploit-DBVexDay Proof
Citrix Metaframe XP - Cross-Site Scripting
CVE-2003-1157remotewindows31 Oct 2003
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
Tritanium Scripts Tritanium Bulletin Board 1.2.3 - Unauthorized Access
CVE-2003-1162webappsphp31 Oct 2003
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying
23RISK
open
Exploit-DBVexDay Proof
Seyeon FlexWATCH Network Video Server 2.2 - Unauthorized Administrative Access
CVE-2003-1160remotehardware31 Oct 2003
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges v
23RISK
open
Exploit-DBVexDay Proof
BEA WebLogic 6/7/8 - InteractiveQuery.jsp Cross-Site Scripting
CVE-2003-0624webappsjsp31 Oct 2003
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
Ledscripts LedForums - Multiple HTML Injections
CVE-2003-1197webappsphp30 Oct 2003
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
BEA Tuxedo 6/7/8 and WebLogic Enterprise 4/5 - Input Validation
CVE-2003-0621remotecgi30 Oct 2003
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files ou
23RISK
open
Exploit-DBVexDay Proof
Serious Sam Engine 1.0.5 - Remote Denial of Service
CVE-2003-1143dosmultiple30 Oct 2003
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05
23RISK
open
Exploit-DBVexDay Proof
E107 - 'Chatbox.php' Denial of Service
CVE-2003-1191dosphp29 Oct 2003
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML i
23RISK
open
Exploit-DBVexDay Proof
Centrinity FirstClass HTTP Server 7.1 - Directory Disclosure
CVE-2003-1173remotemultiple28 Oct 2003
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the
23RISK
open
Exploit-DBVexDay Proof
Fastream NetFile 6.0.3.588 - Error Message Cross-Site Scripting
CVE-2003-1151remotemultiple28 Oct 2003
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
kpopup 0.9.x - Privileged Command Execution
CVE-2003-1167locallinux28 Oct 2003
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their priv
23RISK
open
Exploit-DBVexDay Proof
Yahoo! Messenger 5.6 - File Transfer Buffer Overrun
CVE-2003-1135doswindows27 Oct 2003
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
23RISK
open
Exploit-DBVexDay Proof
Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting
CVE-2003-1136webappsphp27 Oct 2003
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (1)
CVE-2003-0947locallinux27 Oct 2003
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RISK
open
Exploit-DBVexDay Proof
Musicqueue 0.9/1.0/1.1 - Multiple Buffer Overrun Vulnerabilities
CVE-2003-1140locallinux27 Oct 2003
Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the con
23RISK
open
Exploit-DBVexDay Proof
SH-HTTPD 0.3/0.4 - Character Filtering Remote Information Disclosure
CVE-2003-1137remotelinux27 Oct 2003
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a G
23RISK
open
Exploit-DBVexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (3)
CVE-2003-0947locallinux27 Oct 2003
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RISK
open
previouspage 541 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.