Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
CVE-2010-4111webappsphp15 Dec 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-4188remotemultiple14 Dec 2010
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple14 Dec 2010
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-3843remotemultiple14 Dec 2010
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit)
CVE-2010-0806HIGHunder attackremotewindows14 Dec 2010
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2010-4094remotemultiple14 Dec 2010
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-4189remotemultiple14 Dec 2010
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2010-0557remotemultiple14 Dec 2010
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISK
open
Exploit-DBVexDay Proof
Axis2 - (Authenticated) Code Execution (via REST) (Metasploit)
CVE-2010-0219remotemultiple14 Dec 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
Exploit-DBVexDay Proof
Axis2 / SAP BusinessObjects - (Authenticated) Code Execution (via SOAP) (Metasploit)
CVE-2010-0219remotemultiple14 Dec 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
Exploit-DBVexDay Proof
Crystal Reports Viewer 12.0.0.549 - 'PrintControl.dll' ActiveX
CVE-2010-2590remotewindows14 Dec 2010
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISK
open
Exploit-DBVexDay Proof
Clear iSpot/Clearspot 2.0.0.0 - Cross-Site Request Forgery
CVE-2010-4507webappshardware12 Dec 2010
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 a
23RISK
open
Exploit-DBVexDay Proof
Exim 4.63 - Remote Command Execution
CVE-2010-4344CRITICALunder attackremotelinux11 Dec 2010
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple HTML Injection Vulnerabilities
CVE-2010-3770remotelinux09 Dec 2010
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x b
23RISK
open
Exploit-DBVexDay Proof
Apache Archiva 1.0 < 1.3.1 - Cross-Site Request Forgery
CVE-2010-3449webappsmultiple09 Dec 2010
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component JE Auto 1.0 - SQL Injection
CVE-2010-4517webappsphp09 Dec 2010
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - CSS Parser Denial of Service
CVE-2010-3971doswindows08 Dec 2010
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Safe Search - 'v1' Cross-Site Scripting
CVE-2010-4518webappsphp08 Dec 2010
Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordP
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting
CVE-2010-4747webappsphp08 Dec 2010
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5
23RISK
open
Exploit-DBVexDay Proof
Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting
CVE-2010-4513webappsphp07 Dec 2010
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
GNU glibc - 'regcomp()' Stack Exhaustion Denial of Service
CVE-2010-4052doslinux07 Dec 2010
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3,
35RISK
open
Exploit-DBVexDay Proof
Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting
CVE-2010-4513webappsphp07 Dec 2010
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Aigaion 1.3.4 - 'ID' SQL Injection
CVE-2010-4503webappsphp07 Dec 2010
SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
CVE-2010-4258locallinux07 Dec 2010
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs va
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
CVE-2010-3850locallinux07 Dec 2010
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADM
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
CVE-2010-3849locallinux07 Dec 2010
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is con
23RISK
open
Exploit-DBVexDay Proof
phpMyAdmin - Client-Side Code Injection / Redirect Link Falsification
CVE-2010-4480webappsphp06 Dec 2010
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site sc
23RISK
open
Exploit-DBVexDay Proof
UnrealIRCd 3.2.8.1 - Backdoor Command Execution (Metasploit)
CVE-2010-2075remotelinux05 Dec 2010
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
Exploit-DBVexDay Proof
Ecommercemax Solutions Digital Goods Seller - SQL Injection
CVE-2010-4735webappsasp05 Dec 2010
SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote a
23RISK
open
Exploit-DBVexDay Proof
Gatesoft Docusafe 4.1.0 - SQL Injection
CVE-2010-4736webappsasp05 Dec 2010
SQL injection vulnerability in ECO.asp in GateSoft DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary
23RISK
open
previouspage 166 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.