Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'nnmRptConfig.exe schdParams' Remote Buffer Overflow (Metasploit)
CVE-2011-0267remotewindows24 Mar 2011
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' (MaxAge) CGI Buffer Overflow (Metasploit)
CVE-2010-1553remotewindows24 Mar 2011
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
60RISK
open
Exploit-DBVexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe execvp' Remote Buffer Overflow (Metasploit)
CVE-2010-2703remotewindows23 Mar 2011
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM)
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe' Unrecognized Option Buffer Overflow (Metasploit)
CVE-2010-1960remotewindows23 Mar 2011
Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.5
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - nnmRptConfig nameParams Buffer Overflow (Metasploit)
CVE-2011-0266remotewindows23 Mar 2011
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RISK
open
Exploit-DBVexDay Proof
Progea Movicon 11 - 'TCPUploadServer' Remote File System
CVE-2011-2963remotewindows23 Mar 2011
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, whi
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - AVM Bytecode Verification (Metasploit)
CVE-2011-0609HIGHunder attackremotewindows23 Mar 2011
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RISK
open
Exploit-DBVexDay Proof
Perl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of Service
CVE-2010-4777dosmultiple23 Mar 2011
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debuggin
23RISK
open
Exploit-DBVexDay Proof
Advantech/BroadWin SCADA Webaccess 7.0 - Multiple Vulnerabilities
CVE-2011-4041remotemultiple23 Mar 2011
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code
28RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'snmpviewer.exe' Remote Buffer Overflow (Metasploit)
CVE-2010-1552remotewindows23 Mar 2011
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01,
50RISK
open
Exploit-DBVexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe OvJavaLocale' Remote Buffer Overflow (Metasploit)
CVE-2010-2709remotewindows23 Mar 2011
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe ovutil' Remote Buffer Overflow (Metasploit)
CVE-2010-1961remotewindows23 Mar 2011
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remo
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe main' Remote Buffer Overflow (Metasploit)
CVE-2010-1964remotewindows23 Mar 2011
Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.6.x - HFS Subsystem Information Disclosure
CVE-2011-0180localosx21 Mar 2011
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) H
23RISK
open
Exploit-DBVexDay Proof
Novell Netware - NWFTPD.NLM DELE Remote Code Execution
CVE-2010-4228dosnetware21 Mar 2011
Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated
28RISK
open
Exploit-DBVexDay Proof
Douran 3.9.7.8 - File Download/Source Code Disclosure
CVE-2011-1569webappsasp20 Mar 2011
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web ro
23RISK
open
Exploit-DBVexDay Proof
RealNetworks RealPlayer - CDDA URI Initialization (Metasploit)
CVE-2010-3747remotewindows17 Mar 2011
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterpr
50RISK
open
Exploit-DBVexDay Proof
Sun Java Applet2ClassLoader - Remote Code Execution (Metasploit)
CVE-2010-4452remotemultiple16 Mar 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RISK
open
Exploit-DBVexDay Proof
Adobe ColdFusion - Directory Traversal (Metasploit)
CVE-2010-2861CRITICALunder attackransomwareremotemultiple16 Mar 2011
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RISK
open
Exploit-DBVexDay Proof
SugarCRM 6.1.1 - Information Disclosure
CVE-2011-0745webappsphp15 Mar 2011
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain dupl
23RISK
open
Exploit-DBVexDay Proof
HP OpenView Performance Insight Server - Backdoor Account Code Execution (Metasploit)
CVE-2011-0276remotewindows15 Mar 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RISK
open
Exploit-DBVexDay Proof
Google Android 2.0/2.1/2.1.1 - WebKit Use-After-Free
CVE-2010-1119remoteandroid14 Mar 2011
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari befo
28RISK
open
Exploit-DBVexDay Proof
PHP 5.3.6 - 'shmop_read()' Integer Overflow Denial of Service
CVE-2011-1092doslinux12 Mar 2011
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of servic
28RISK
open
Exploit-DBVexDay Proof
PHP < 5.3.6 'Zip' Extension - 'zip_fread()' Denial of Service
CVE-2011-1471dosphp10 Mar 2011
Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to
28RISK
open
Exploit-DBVexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - 'rxsSetDataGrowthScheduleAndFilter' Remote Buffer Overflow (Metasploit)
CVE-2007-3216remotewindows10 Mar 2011
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops a
50RISK
open
Exploit-DBVexDay Proof
SmarterMail 7.3/7.4 - Multiple Vulnerabilities
CVE-2010-3486webappsasp10 Mar 2011
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISK
open
Exploit-DBVexDay Proof
PHP 5.3.x 'Intl' Extension - 'NumberFormatter::setSymbol()' Denial of Service
CVE-2011-1467dosphp10 Mar 2011
Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PH
28RISK
open
Exploit-DBVexDay Proof
PHP 5.3.x 'Zip' Extension - 'stream_get_contents()' Denial of Service
CVE-2011-1470dosphp10 Mar 2011
The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash
23RISK
open
Exploit-DBVexDay Proof
Xinha 0.96 - 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities
CVE-2011-5267webappsphp10 Mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as
23RISK
open
Exploit-DBVexDay Proof
WebKit 1.2.x - Local Webpage Cross Domain Information Disclosure
CVE-2011-0167remotewindows09 Mar 2011
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Polic
23RISK
open
previouspage 159 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.