Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,210cataloged exploits
36,420CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
CVE-2012-5244webappsphp21 Dec 2012
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
InduSoft Web Studio - 'ISSymbol.ocx InternationalSeparator()' Heap Overflow (Metasploit)
CVE-2011-0340remotewindows20 Dec 2012
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RISK
open
Exploit-DBVexDay Proof
Crystal Reports CrystalPrintControl - ActiveX ServerResourceVersion Property Overflow (Metasploit)
CVE-2010-2590remotewindows18 Dec 2012
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISK
open
Exploit-DBVexDay Proof
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
CVE-2013-1744webappsphp17 Dec 2012
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.3.5 - Btrfs CRC32C feature Infinite Loop Local Denial of Service
CVE-2012-5375doslinux13 Dec 2012
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial o
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Portable phpMyAdmin - Authentication Bypass
CVE-2012-5469webappsphp13 Dec 2012
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain ph
28RISK
open
Exploit-DBVexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4957remotewindows12 Dec 2012
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RISK
open
Exploit-DBVexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4959remotewindows12 Dec 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RISK
open
Exploit-DBVexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4958remotewindows12 Dec 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RISK
open
Exploit-DBVexDay Proof
HP Data Protector - DtbClsLogin Buffer Overflow (Metasploit)
CVE-2010-3007remotewindows11 Dec 2012
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x befo
38RISK
open
Exploit-DBVexDay Proof
SimpleInvoices invoices Module - Customer Field Cross-Site Scripting
CVE-2012-4932webappsphp10 Dec 2012
Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attacker
23RISK
open
Exploit-DBVexDay Proof
Smartphone Pentest Framework - Multiple Remote Command Execution Vulnerabilities
CVE-2012-5878webappscgi10 Dec 2012
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman
23RISK
open
Exploit-DBVexDay Proof
Achievo 1.4.5 - Multiple Vulnerabilities (2)
CVE-2012-5865webappsphp09 Dec 2012
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Google Android Kernel 2.6 - Local Denial of Service Crash (PoC)
CVE-2013-1773dosandroid09 Dec 2012
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileg
23RISK
open
Exploit-DBVexDay Proof
SumatraPDF 2.1.1/MuPDF 1.0 - Integer Overflow
CVE-2012-5340doswindows09 Dec 2012
SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corru
23RISK
open
Exploit-DBVexDay Proof
IBM System Director Agent - DLL Injection (Metasploit)
CVE-2009-0880remotewindows07 Dec 2012
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.0.4 - '.swf' Crash (PoC)
CVE-2013-1868doswindows07 Dec 2012
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of ser
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Simple Gmail Login - Stack Trace Information Disclosure
CVE-2012-6313webappsphp07 Dec 2012
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sen
23RISK
open
Exploit-DBVexDay Proof
Oracle MySQL (Windows) - MOF Execution (Metasploit)
CVE-2012-5613remotewindows06 Dec 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISK
open
Exploit-DBVexDay Proof
Oracle MySQL / MariaDB - Insecure Salt Generation Security Bypass
CVE-2012-5627remotelinux06 Dec 2012
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt duri
28RISK
open
Exploit-DBVexDay Proof
(SSH.com Communications) SSH Tectia - USERAUTH Change Request Password Reset (Metasploit)
CVE-2012-5975remoteunix05 Dec 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RISK
open
Exploit-DBVexDay Proof
Ektron 8.02 - XSLT Transform Remote Code Execution (Metasploit)
CVE-2012-5357remotewindows05 Dec 2012
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RISK
open
Exploit-DBVexDay Proof
Advantech Studio 7.0 - SCADA/HMI Directory Traversal
CVE-2013-1627webappswindows04 Dec 2012
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and
23RISK
open
Exploit-DBVexDay Proof
Opera Web Browser 12.11 - Crash (PoC)
CVE-2012-6470doswindows03 Dec 2012
Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
MySQL 5.1/5.5 (Windows) - 'MySQLJackpot' Remote Command Execution
CVE-2012-5615remotewindows02 Dec 2012
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RISK
open
Exploit-DBVexDay Proof
MySQL - Remote User Enumeration
CVE-2012-5615remotemultiple02 Dec 2012
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RISK
open
Exploit-DBVexDay Proof
freeFTPd 1.2.6 - Remote Authentication Bypass
CVE-2012-6066remotewindows02 Dec 2012
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RISK
open
Exploit-DBVexDay Proof
MySQL (Linux) - Database Privilege Escalation
CVE-2012-5613locallinux02 Dec 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISK
open
Exploit-DBVexDay Proof
freeSSHd 2.1.3 - Remote Authentication Bypass
CVE-2012-6066remotewindows02 Dec 2012
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RISK
open
Exploit-DBVexDay Proof
(SSH.com Communications) SSH Tectia (SSH < 2.0-6.1.9.95 / Tectia 6.1.9.95) - Remote Authentication Bypass
CVE-2012-5975remotelinux02 Dec 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RISK
open
previouspage 114 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.