Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2011-0748webappsphp26 Jan 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack th
23RISK
open
Exploit-DBVexDay Proof
phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2012-5228webappsphp26 Jan 2012
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions befo
23RISK
open
Exploit-DBVexDay Proof
phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2012-4246webappsphp26 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta
23RISK
open
Exploit-DBVexDay Proof
phpList 2.10.9 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2012-4247webappsphp26 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in lists/admin/index.php in phpList before 2.10.19 allow remote atta
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Slideshow Gallery 1.1.x - 'border' Cross-Site Scripting
CVE-2012-5229webappsphp26 Jan 2012
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows re
23RISK
open
Exploit-DBVexDay Proof
OSClass 2.3.3 - 'index.php?sCategory' SQL Injection
CVE-2012-0973webappsphp25 Jan 2012
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2012-0937webappsphp25 Jan 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQ
23RISK
open
Exploit-DBVexDay Proof
vBadvanced CMPS 3.2.2 - 'vba_cmps_include_bottom.php' Remote File Inclusion
CVE-2012-5224webappsphp25 Jan 2012
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2012-0782webappsphp25 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPr
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2011-4898webappsphp25 Jan 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error message
23RISK
open
Exploit-DBVexDay Proof
OSClass 2.3.3 - 'index.php?getParam()' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-0974webappsphp25 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in O
23RISK
open
Exploit-DBVexDay Proof
DClassifieds 0.1 final - Cross-Site Request Forgery
CVE-2012-0990webappsphp25 Jan 2012
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2011-4899webappsphp25 Jan 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specifie
23RISK
open
Exploit-DBVexDay Proof
stoneware webnetwork6 - Multiple Vulnerabilities
CVE-2012-0285webappsjsp24 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
stoneware webnetwork6 - Multiple Vulnerabilities
CVE-2012-0286webappsjsp24 Jan 2012
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin YouSayToo auto-publishing 1.0 - 'submit' Cross-Site Scripting
CVE-2012-0901webappsphp24 Jan 2012
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows r
38RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.39 < 3.2.2 (Gentoo / Ubuntu x86/x64) - 'Mempodipper' Local Privilege Escalation (1)
CVE-2012-0056locallinux23 Jan 2012
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RISK
open
Exploit-DBVexDay Proof
Lead Capture - 'login.php' Script Cross-Site Scripting
CVE-2012-0932webappsphp21 Jan 2012
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
PHP iReport 1.0 - Remote Html Code Injection
CVE-2012-5315webappsphp21 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Tribiq CMS - 'index.php' SQL Injection
CVE-2012-5312webappsphp21 Jan 2012
SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Vik Real Estate 1.0 - Multiple SQL Injections
CVE-2011-4823webappsphp21 Jan 2012
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote att
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_kp - 'Controller' Local File Inclusion
CVE-2011-4804webappsphp21 Jan 2012
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attack
43RISK
open
Exploit-DBVexDay Proof
Acidcat ASP CMS 3.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-0933webappsasp21 Jan 2012
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remot
23RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager - 'ov.dll' _OVBuildPath Buffer Overflow (Metasploit)
CVE-2011-3167remotewindows20 Jan 2012
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute
50RISK
open
Exploit-DBVexDay Proof
ICTimeAttendance - Authentication Bypass
CVE-2012-0913webappsasp20 Jan 2012
SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Snitz Forums 2000 - 'TOPIC_ID' SQL Injection
CVE-2012-5313webappsasp20 Jan 2012
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
OneOrZero AIMS - 'index.php' Cross-Site Scripting
CVE-2012-0989webappsphp18 Jan 2012
Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows r
23RISK
open
Exploit-DBVexDay Proof
DZCP (deV!L_z Clanportal) Gamebase Addon - SQL Injection
CVE-2012-0905webappsphp18 Jan 2012
SQL injection vulnerability in deV!L'z Clanportal (DZCP) Gamebase addon allows remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
pGB 2.12 - 'kommentar.php' SQL Injection
CVE-2012-6524webappsphp18 Jan 2012
SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
PHPBridges Blog System - 'members.php' SQL Injection
CVE-2012-6525webappsphp18 Jan 2012
SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
previouspage 140 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.