Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Microsoft Unicode Scripts Processor - Remote Code Execution (MS10-063)
CVE-2010-2738doswindows30 Sep 2010
The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server
28RISK
open
Exploit-DBVexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
CVE-2010-4865webappsphp30 Sep 2010
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
MODx manager - '/controllers/default/resource/tvs.php?class_key' Traversal Local File Inclusion
CVE-2010-5278webappsphp29 Sep 2010
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc6 (RedHat / Ubuntu 10.04) - 'pktcdvd' Kernel Memory Disclosure
CVE-2010-3437locallinux29 Sep 2010
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RISK
open
Exploit-DBVexDay Proof
MyPhpAuction 2010 - 'id' SQL Injection
CVE-2010-4860webappsphp29 Sep 2010
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Webspell 4.2.1 - 'asearch.php' SQL Injection
CVE-2010-4861webappsphp29 Sep 2010
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
MODx 2.0.2-pl - '/manager/index.php?modahsh' Cross-Site Scripting
CVE-2010-4883webappsphp29 Sep 2010
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - SxView Record Parsing Heap Memory Corruption
CVE-2010-1245doswindows29 Sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML Fil
28RISK
open
Exploit-DBVexDay Proof
Getsimple CMS 2.01 - 'changedata.php' Cross-Site Scripting
CVE-2010-4863webappsphp29 Sep 2010
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
XFS - Deleted Inode Local Information Disclosure
CVE-2010-2943locallinux29 Sep 2010
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode b
28RISK
open
Exploit-DBVexDay Proof
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
CVE-2007-1748remotewindows28 Sep 2010
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISK
open
Exploit-DBVexDay Proof
PHPMyFAQ 2.6.x - 'index.php' Cross-Site Scripting
CVE-2010-4821webappsphp28 Sep 2010
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'Winhlp32.exe' MsgBox Code Execution (MS10-023) (Metasploit)
CVE-2010-0483remotewindows28 Sep 2010
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RISK
open
Exploit-DBVexDay Proof
Horde IMP Webmail 4.3.7 - 'fetchmailprefs.php' HTML Injection
CVE-2010-3695webappsphp27 Sep 2010
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Ed
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML Findtext Processing
CVE-2010-2553doswindows27 Sep 2010
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISK
open
Exploit-DBVexDay Proof
Entrans - SQL Injection
CVE-2010-4935webappsphp27 Sep 2010
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
CVE-2010-0094remotemultiple27 Sep 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RISK
open
Exploit-DBVexDay Proof
Blue River Mura CMS - Directory Traversal
CVE-2010-3468webappscfm26 Sep 2010
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RISK
open
Exploit-DBVexDay Proof
Microsoft Cinepak Codec CVDecompress - Heap Overflow (MS10-055)
CVE-2010-2553doswindows26 Sep 2010
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISK
open
Exploit-DBVexDay Proof
Adobe Illustrator CS4 14.0.0 - Postscript (.eps) Buffer Overflow (Metasploit)
CVE-2009-4195localwindows25 Sep 2010
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu
60RISK
open
Exploit-DBVexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
CVE-2009-3214localwindows25 Sep 2010
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2)
CVE-2009-4324HIGHunder attacklocalwindows25 Sep 2010
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before
100RISK
open
Exploit-DBVexDay Proof
PointDev IDEAL Migration - Buffer Overflow (Metasploit)
CVE-2009-4265dosaix25 Sep 2010
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISK
open
Exploit-DBVexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
CVE-2008-2992HIGHunder attackransomwarelocalwindows25 Sep 2010
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat - Bundled LibTIFF Integer Overflow (Metasploit)
CVE-2010-0188HIGHunder attackransomwarelocalwindows25 Sep 2010
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
CVE-2010-1297HIGHunder attacklocalwindows25 Sep 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISK
open
Exploit-DBVexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
CVE-2007-4776localwindows25 Sep 2010
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISK
open
Exploit-DBVexDay Proof
ACDSee - '.XPM' File Section Buffer Overflow (Metasploit)
CVE-2007-2193localwindows25 Sep 2010
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RISK
open
Exploit-DBVexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)
CVE-2009-3459HIGHunder attacklocalwindows25 Sep 2010
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open
Exploit-DBVexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2)
CVE-2009-3953HIGHunder attacklocalwindows25 Sep 2010
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open
previouspage 176 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.