Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,453cataloged exploits
37,908CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Powie PForum 1.1x - 'Username' Cross-Site Scripting
CVE-2002-0319—webappsphp22 Feb 2002
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Squid 2.0-4 - Cache FTP Proxy URL Buffer Overflow
CVE-2002-0068—remoteunix21 Feb 2002
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbi
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
CVE-2001-0925—remotemultiple21 Feb 2002
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗
Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - Symbolic Link
CVE-2002-0296—localunix19 Feb 2002
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open ↗
Exploit-DB✓ VexDay Proof
GNUJSP 1.0 - File Disclosure
CVE-2002-0300—remotemultiple19 Feb 2002
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass acce
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (1)
CVE-2002-0288—remotewindows16 Feb 2002
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Icecast 1.x - AVLLib Buffer Overflow
CVE-2002-0177—remoteunix16 Feb 2002
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (2)
CVE-2002-0288—remotewindows16 Feb 2002
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Long URL Denial of Service
CVE-2002-0289—doswindows16 Feb 2002
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
CVE-2002-0289—remotewindows16 Feb 2002
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Ettercap 0.6.3.1 - Large Packet Buffer Overflow
CVE-2002-0276—remotelinux14 Feb 2002
Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Cisco IOS 11/12 - SNMP Message Denial of Service
CVE-2002-0013—doshardware12 Feb 2002
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause
35RISK
open ↗
Exploit-DB✓ VexDay Proof
Sawmill 6.2.x - Admin Password Insecure Default Permissions
CVE-2002-0265—localmultiple11 Feb 2002
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows loca
23RISK
open ↗
Exploit-DB✓ VexDay Proof
EZNE.NET Ezboard 2000 - Remote Buffer Overflow
CVE-2002-0263—remotecgi11 Feb 2002
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long bounda
28RISK
open ↗
Exploit-DB✓ VexDay Proof
HP AdvanceStack Switch - Authentication Bypass
CVE-2002-0250—remotehardware08 Feb 2002
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allow
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 5.0 - Content-Type Remote Buffer Overflow
CVE-2002-0252—remotewindows08 Feb 2002
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - gunzip Race Condition
CVE-2002-0211—localunix08 Feb 2002
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable tempor
23RISK
open ↗
Exploit-DB✓ VexDay Proof
OS/400 - User Account Name Disclosure
CVE-2002-1731—localmultiple07 Feb 2002
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (1)
CVE-2002-0239—locallinux07 Feb 2002
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Caldera UnixWare 7.1.1 - Message Catalog Environment Variable Format String
CVE-2002-0246—localunixware07 Feb 2002
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privil
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (2)
CVE-2002-0239—locallinux07 Feb 2002
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISK
open ↗
Exploit-DB✓ VexDay Proof
AtheOS 0.3.7 - Change Root Directory Escaping
CVE-2002-0244—localatheos07 Feb 2002
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot d
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sambar Server 5.1 - Sample Script Denial of Service
CVE-2002-0128—doswindows06 Feb 2002
cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execut
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Thunderstone TEXIS 3.0 - Full Path Disclosure
CVE-2002-0266—remotemultiple06 Feb 2002
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexi
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ICQ For Mac OSX 2.6 Client - Denial of Service
CVE-2002-1773—dososx05 Feb 2002
Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and pos
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'index.php' Directory Traversal
CVE-2002-2084—webappsphp04 Feb 2002
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Faq-O-Matic 2.6/2.7 - Cross-Site Scripting
CVE-2002-0230—remotecgi04 Feb 2002
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascri
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'view.php' Directory Traversal
CVE-2002-2084—webappsphp04 Feb 2002
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (3)
CVE-2004-0327—remotephp03 Feb 2002
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary
23RISK
open ↗
Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (2)
CVE-2002-0229—remotephp03 Feb 2002
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe
23RISK
open ↗
← previouspage 580 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.