Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (1)
CVE-2003-0281—localunix15 Jun 2002
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase code
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (1)
CVE-2002-2087—localunix15 Jun 2002
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment v
23RISK
open ↗
Exploit-DB✓ VexDay Proof
My Postcards 6.0 - 'MagicCard.cgi' Arbitrary File Disclosure
CVE-2002-1966—webappscgi15 Jun 2002
Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Cisco Secure ACS for Windows NT 3.0 - Cross-Site Scripting
CVE-2002-0938—remotewindows14 Jun 2002
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Mewsoft NetAuction 3.0 - Cross-Site Scripting
CVE-2002-1703—webappscgi14 Jun 2002
Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHP Classifieds 6.0.5 - Cross-Site Scripting
CVE-2002-1702—webappsphp14 Jun 2002
Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitr
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 - Password Encrypt procedure Buffer Overflow
CVE-2002-0624—localwindows14 Jun 2002
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Lumigent Log Explorer 3.0.1 - XP_LogAttach_SetPort Buffer Overflow
CVE-2002-0942—localwindows14 Jun 2002
Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary cod
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Lumigent Log Explorer XP - _LogAttach_StartProf Buffer Overflow
CVE-2002-0942—localwindows14 Jun 2002
Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary cod
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Imatix Xitami 2.5 - GSL Template Cross-Site Scripting
CVE-2002-1965—remotewindows14 Jun 2002
Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to injec
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Ruslan Communications <Body>Builder - Authentication Bypass
CVE-2002-0951—webappsjava13 Jun 2002
SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Working Resources 1.7.3 BadBlue - Null Byte File Disclosure
CVE-2002-1021—remotewindows13 Jun 2002
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a he
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ColdFusion MX - Missing Template Cross-Site Scripting
CVE-2002-1700—remotecfm13 Jun 2002
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attac
28RISK
open ↗
Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.16 - Web Server Buffer Overflow
CVE-2002-0968—remotewindows13 Jun 2002
Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Netscape 4.77 - Composer Font Face Field Buffer Overflow
CVE-2002-1766—dosmultiple13 Jun 2002
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code v
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Netscape 4.x/6.x / Mozilla 0.9.x - Malformed Email POP3 Denial of Service
CVE-2002-2338—dosmultiple12 Jun 2002
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to c
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache Tomcat 3/4 - JSP Engine Denial of Service
CVE-2002-0936—doslinux12 Jun 2002
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the w
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Ayman Akt IRCIT 0.3.1 - Invite Message Remote Buffer Overflow
CVE-2002-1891—doslinux12 Jun 2002
Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Richard Gooch SimpleInit 2.0.2 - Open File Descriptor
CVE-2002-0767—locallinux12 Jun 2002
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allo
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MakeBook 2.2 - Form Field Input Validation
CVE-2002-0948—webappscgi12 Jun 2002
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute s
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 - 'SQLXML' Buffer Overflow (PoC)
CVE-2002-0186—doswindows12 Jun 2002
Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary
35RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 - SQLXML Script Injection
CVE-2002-0187—remotewindows12 Jun 2002
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute ar
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Macromedia JRun 3/4 JSP Engine - Denial of Service
CVE-2002-0937—doswindows12 Jun 2002
The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web
23RISK
open ↗
Exploit-DB✓ VexDay Proof
CGIScript.net csNews 1.0 - Header File Type Restriction Bypass
CVE-2002-0923—webappscgi11 Jun 2002
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via th
23RISK
open ↗
Exploit-DB✓ VexDay Proof
CGIScript.net csNews 1.0 - Double URL Encoding Unauthorized Administrative Access
CVE-2002-0922—webappscgi11 Jun 2002
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) defaul
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 8 dtspcd - Remote Heap Overflow (Metasploit)
CVE-2001-0803—remotesolaris10 Jun 2002
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remo
60RISK
open ↗
Exploit-DB✓ VexDay Proof
W-Agora 4.1.x - Remote File Inclusion
CVE-2002-1878—webappsphp10 Jun 2002
PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the i
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MyHelpDesk 20020509 - Cross-Site Scripting
CVE-2002-0931—webappsphp10 Jun 2002
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to exe
23RISK
open ↗
Exploit-DB✓ VexDay Proof
MyHelpDesk 20020509 - HTML Injection
CVE-2002-0931—webappsphp10 Jun 2002
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to exe
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Geeklog 1.3.5 - Calendar Event Form Script Injection
CVE-2002-0962—webappsphp10 Jun 2002
Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via
23RISK
open ↗
← previouspage 573 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.