Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
SurfControl SuperScout Email Filter 3.5 - 'MsgError.asp' Cross-Site Scripting
CVE-2002-1529—webappsasp08 Oct 2002
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Killer Protection 1.0 - Information Disclosure
CVE-2002-2335—webappsphp07 Oct 2002
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Help Facility ActiveX Control Buffer Overflow
CVE-2002-0693—remotewindows07 Oct 2002
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edi
35RISK
open ↗
Exploit-DB✓ VexDay Proof
ghttpd 1.4.x - 'Log()' Remote Buffer Overflow
CVE-2001-0820—remotelinux07 Oct 2002
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Oracle 9i Application Server 9.0.2 Web Cache Administration Tool - Denial of Service
CVE-2002-0386—dosmultiple06 Oct 2002
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cau
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (3)
CVE-2002-1522—doswindows05 Oct 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (2)
CVE-2002-1522—doswindows05 Oct 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (1)
CVE-2002-1522—doswindows05 Oct 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISK
open ↗
Exploit-DB✓ VexDay Proof
ATP HTTPd 0.4 - Single Byte Buffer Overflow
CVE-2002-1816CRITICALremotelinux05 Oct 2002
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers
48RISK
open ↗
Exploit-DB✓ VexDay Proof
phpLinkat 0.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-2321—webappsphp04 Oct 2002
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote att
23RISK
open ↗
Exploit-DB✓ VexDay Proof
phpMyNewsletter 0.6.10 - Remote File Inclusion
CVE-2002-1887—webappsphp03 Oct 2002
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Midicart PHP - Information Disclosure
CVE-2002-1798—webappsphp02 Oct 2002
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting
CVE-2002-2178—webappsphp02 Oct 2002
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Py-Membres 3.1 - 'index.php' Unauthorized Access
CVE-2002-1884—webappsphp02 Oct 2002
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
TightAuction 3.0 - Config.INC Information Disclosure
CVE-2002-1886—webappsphp02 Oct 2002
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote att
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Midicart PHP - Arbitrary File Upload
CVE-2002-1798—webappsphp02 Oct 2002
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution
CVE-2002-1178—webappscgi02 Oct 2002
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execut
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - Remote Readable Administrator Password
CVE-2002-2143—webappsphp02 Oct 2002
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3/2.0.x - Server Side Include Cross-Site Scripting
CVE-2002-0840—remotemultiple02 Oct 2002
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26,
45RISK
open ↗
Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - SQL Injection
CVE-2002-0709—remotewindows02 Oct 2002
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to e
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - File Disclosure
CVE-2002-0708—remotewindows02 Oct 2002
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - PHP Injection
CVE-2002-2319—webappsphp02 Oct 2002
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code an
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - SMRSH Double Pipe Access Validation
CVE-2002-1165—localunix01 Oct 2002
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 fro
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal
CVE-2002-1525—webappsjava30 Sep 2002
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to r
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Rogue 5.3 - Local Buffer Overflow
CVE-2002-1192—localbsd30 Sep 2002
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1/0.4/0.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-1852—remotemultiple30 Sep 2002
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗
Exploit-DB✓ VexDay Proof
EmuMail 5.0 Email Form - Script Injection
CVE-2002-1526—webappscgi29 Sep 2002
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary
23RISK
open ↗
Exploit-DB✓ VexDay Proof
EmuMail 5.0 - Web Root Full Path Disclosure
CVE-2002-1527—webappscgi29 Sep 2002
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed st
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SafeTP 1.46 - Passive Mode Internal IP Address Revealing
CVE-2002-1943—remotemultiple28 Sep 2002
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Jetty 4.1 Servlet Engine - Cross-Site Scripting
CVE-2002-1533—webappsjsp28 Sep 2002
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or
23RISK
open ↗
← previouspage 564 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.