Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
DIY CMS 1.0 Poll - Multiple Vulnerabilities
CVE-2012-6518webappsphp30 Apr 2012
Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authenti
23RISK
open
Exploit-DBVexDay Proof
McAfee Virtual Technician 6.3.0.1911 MVT.MVTControl.6300 - ActiveX 'GetObject()' Code Execution
CVE-2012-4598remotewindows30 Apr 2012
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to ex
43RISK
open
Exploit-DBVexDay Proof
DIY CMS 1.0 Poll - Multiple Vulnerabilities
CVE-2012-6517webappsphp30 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Remote-Anything Player 5.60.15 - Denial of Service
CVE-2012-4057doswindows29 Apr 2012
Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted
23RISK
open
Exploit-DBVexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-2599webappsphp29 Apr 2012
20RISK
open
Exploit-DBVexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-3834webappsphp29 Apr 2012
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OS
23RISK
open
Exploit-DBVexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-3835webappsphp29 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.
23RISK
open
Exploit-DBVexDay Proof
WebCalendar 1.2.4 - Remote Code Injection (Metasploit)
CVE-2012-1495webappslinux29 Apr 2012
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'main.php' Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-4252webappsphp27 Apr 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the au
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'sql.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-4251webappsphp27 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'install.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-4251webappsphp27 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
XM Forum - 'id' Multiple SQL Injections
CVE-2012-4060webappsasp27 Apr 2012
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Uiga FanClub - 'p' SQL Injection
CVE-2012-4055webappsphp27 Apr 2012
SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'filemanagement.php?f' Traversal Arbitrary File Access
CVE-2012-4253webappsphp27 Apr 2012
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RISK
open
Exploit-DBVexDay Proof
Nokia PC Suite Video Manager 7.1.180.64 - '.mp4' Denial of Service
CVE-2012-2442doswindows27 Apr 2012
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'restore.php?Filename' Cross-Site Scripting
CVE-2012-4251webappsphp27 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'index.php?page' Cross-Site Scripting
CVE-2012-4251webappsphp27 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - 'install.php?language' Traversal Arbitrary File Access
CVE-2012-4253webappsperl27 Apr 2012
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RISK
open
Exploit-DBVexDay Proof
CPE17 Autorun Killer 1.7.1 - Local Stack Buffer Overflow (Metasploit)
CVE-2012-4054localwindows27 Apr 2012
Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers
23RISK
open
Exploit-DBVexDay Proof
MySQLDumper 1.24.4 - Multiple Script Direct Request Information Disclosures
CVE-2012-4254webappsphp27 Apr 2012
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/c
23RISK
open
Exploit-DBVexDay Proof
PHP Volunteer management 1.0.2 - Multiple Vulnerabilities
CVE-2012-6505webappsphp26 Apr 2012
Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remot
23RISK
open
Exploit-DBVexDay Proof
gpEasy 2.3.3 - 'jsoncallback' Cross-Site Scripting
CVE-2012-6513webappsphp26 Apr 2012
Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to i
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Zingiri Web Shop 2.4.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-6506webappsphp26 Apr 2012
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote atta
23RISK
open
Exploit-DBVexDay Proof
PHP Volunteer management 1.0.2 - Multiple Vulnerabilities
CVE-2012-6504webappsphp26 Apr 2012
SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
mount.cifs - 'chdir()' Arbitrary Root File Identification
CVE-2012-1586locallinux25 Apr 2012
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the fil
23RISK
open
Exploit-DBVexDay Proof
Shadow Stream Recorder 3.0.1.7 - Local Buffer Overflow (Metasploit)
CVE-2009-1642localwindows25 Apr 2012
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - MSCOMCTL ActiveX Buffer Overflow (MS12-027) (Metasploit)
CVE-2012-0158HIGHunder attackremotewindows25 Apr 2012
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RISK
open
Exploit-DBVexDay Proof
PHP Ticket System Beta 1 - 'index.php?p' SQL Injection
CVE-2012-6516webappsphp24 Apr 2012
SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component CCNewsLetter 1.0.7 - 'id' SQL Injection
CVE-2011-5099webappsphp23 Apr 2012
SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for
23RISK
open
Exploit-DBVexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
CVE-2012-1496webappsphp23 Apr 2012
Local file inclusion in WebCalendar before 1.2.5.
23RISK
open
previouspage 129 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.