Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,270cataloged exploits
37,818CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Visual Basic For Applications SDK 5.0/6.0/6.2/6.3 - Document Handling Buffer Overrun
CVE-2003-0347—remotewindows03 Sep 2003
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3
35RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft WordPerfect - Converter Buffer Overrun
CVE-2003-0666—localwindows03 Sep 2003
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data o
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Access 97/2000/2002 Snapshot Viewer - ActiveX Control Parameter Buffer Overflow
CVE-2003-0665—remotewindows03 Sep 2003
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote
35RISK
open ↗
Exploit-DB✓ VexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Cross-Site Scripting
CVE-2003-0749—remotemultiple30 Aug 2003
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows r
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Information Disclosure
CVE-2003-0747—remotemultiple30 Aug 2003
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensiti
23RISK
open ↗
Exploit-DB✓ VexDay Proof
sap internet transaction server 4620.2.0.323011 build 46b.323011 - Directory Traversal
CVE-2003-0748—remotemultiple30 Aug 2003
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Linux pam_lib_smb < 1.1.6 - '/bin/login' Remote Overflow
CVE-2003-0686—remotelinux29 Aug 2003
Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote at
28RISK
open ↗
Exploit-DB✓ VexDay Proof
GtkFtpd 1.0.4 - Remote Buffer Overflow
CVE-2003-0755—remotelinux28 Aug 2003
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Tellurian TftpdNT 1.8/2.0 - 'Filename' Buffer Overrun
CVE-2003-0729—remotewindows27 Aug 2003
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a lon
28RISK
open ↗
Exploit-DB✓ VexDay Proof
eNdonesia 8.2/8.3 - 'Mod' Cross-Site Scripting
CVE-2003-1317—webappsphp27 Aug 2003
Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web scr
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access
CVE-2003-0752—webappsphp26 Aug 2003
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to b
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Real Server 7/8/9 (Windows / Linux) - Remote Code Execution
CVE-2003-0725—remotemultiple25 Aug 2003
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetwor
35RISK
open ↗
Exploit-DB✓ VexDay Proof
OptiSoft Blubster 2.5 - Remote Denial of Service
CVE-2003-0760—doswindows25 Aug 2003
Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Avant Browser 8.0.2 - 'HTTP Request' Buffer Overflow (PoC)
CVE-2003-1321—dosmultiple21 Aug 2003
Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Data Remote (MS03-032)
CVE-2003-0701—remotewindows21 Aug 2003
Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) all
35RISK
open ↗
Exploit-DB✓ VexDay Proof
RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution
CVE-2003-0726—remotewindows19 Aug 2003
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation wit
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server - System
CVE-2003-1030—localwindows13 Aug 2003
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Oracle XDB FTP Service - UNLOCK Buffer Overflow
CVE-2003-0727—remotewindows13 Aug 2003
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting
CVE-2003-0736—webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection
CVE-2003-0735—webappsphp11 Aug 2003
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - Remote Command Execution
CVE-2003-0466—remotelinux11 Aug 2003
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RISK
open ↗
Exploit-DB✓ VexDay Proof
PHPOutsourcing Zorum 3.4 - Full Path Disclosure
CVE-2003-1089—webappsphp11 Aug 2003
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names,
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHPOutSourcing Zorum 3.x - Cross-Site Scripting
CVE-2003-1088—webappsphp11 Aug 2003
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - DCOM RPC Interface Buffer Overrun
CVE-2003-0352—remotewindows11 Aug 2003
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RISK
open ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting
CVE-2003-0736—webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting
CVE-2003-0736—webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting
CVE-2003-0736—webappsphp11 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Cisco IOS 12.x/11.x - HTTP Remote Integer Overflow
CVE-2003-0647—remotehardware10 Aug 2003
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting
CVE-2004-1957—webappsphp08 Aug 2003
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web sc
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
CVE-2004-2131—localunix08 Aug 2003
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RISK
open ↗
← previouspage 545 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.