Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
PaysiteReviewCMS 1.1 - 'search.php' Cross-Site Scripting
CVE-2010-4909webappsphp14 Sep 2010
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
PaysiteReviewCMS - 'image.php' Cross-Site Scripting
CVE-2010-4909webappsphp14 Sep 2010
Multiple cross-site scripting (XSS) vulnerabilities in PaysiteReviewCMS 1.1 allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
IBM Lotus Domino iCalendar - Email Address Stack Buffer Overflow
CVE-2010-3407remotemultiple14 Sep 2010
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server i
50RISK
open
Exploit-DBVexDay Proof
Kingsoft AntiVirus 2010.04.26.648 - Kernel Buffer Overflow
CVE-2010-3396doswindows13 Sep 2010
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary co
23RISK
open
Exploit-DBVexDay Proof
UCenter Home 2.0 - SQL Injection
CVE-2010-4912webappsphp13 Sep 2010
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
Group Office 3.5.9 - SQL Injection
CVE-2010-3428webappsphp13 Sep 2010
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
RealPlayer - FLV Parsing Integer Overflow
CVE-2010-3000doswindows13 Sep 2010
Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP
23RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat and Reader - 'pushstring' Memory Corruption
CVE-2010-2201localwindows12 Sep 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISK
open
Exploit-DBVexDay Proof
eshtery CMS - SQL Injection
CVE-2010-3404webappsasp12 Sep 2010
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Microsoft Word 2007 SP2 - sprmCMajority Buffer Overflow
CVE-2010-1900doswindows11 Sep 2010
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Con
35RISK
open
Exploit-DBVexDay Proof
Webkit (Apple Safari < 4.1.2/5.0.2 / Google Chrome < 5.0.375.125) - Memory Corruption
CVE-2010-1813doswindows10 Sep 2010
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion
CVE-2010-3426webappsphp10 Sep 2010
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remo
43RISK
open
Exploit-DBVexDay Proof
Excel RTD - Memory Corruption
CVE-2010-1246localwindows10 Sep 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an
28RISK
open
Exploit-DBVexDay Proof
Excel RTD - Memory Corruption
CVE-2010-1247localwindows10 Sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Ex
28RISK
open
Exploit-DBVexDay Proof
Datetopia Buy Dating Site - Cross-Site Scripting
CVE-2009-3355webappsphp10 Sep 2010
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inje
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.6.3 - XSLT Sort Remote Code Execution
CVE-2010-1199doswindows09 Sep 2010
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4,
28RISK
open
Exploit-DBVexDay Proof
festos CMS 2.3b - Multiple Vulnerabilities
CVE-2010-4893webappsphp09 Sep 2010
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
ES Simple Download 1.0. - Local File Inclusion
CVE-2010-3456webappsphp09 Sep 2010
Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to r
23RISK
open
Exploit-DBVexDay Proof
Microsoft Visio 2002 - '.DXF' Local Stack Overflow
CVE-2010-1681localwindows08 Sep 2010
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RISK
open
Exploit-DBVexDay Proof
Internet Download Accelerator 5.8 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows07 Sep 2010
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
Exploit-DBVexDay Proof
ColdUserGroup 1.06 - Blind SQL Injection
CVE-2010-4913webappswindows07 Sep 2010
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
ZenPhoto 1.3 - '/zp-core/full-image.php?a' SQL Injection
CVE-2010-4906webappsphp07 Sep 2010
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
ColdCalendar 2.06 - SQL Injection
CVE-2010-4910webappswindows07 Sep 2010
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
ZenPhoto 1.3 - '/zp-core/admin.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-4907webappsphp07 Sep 2010
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
ColdUserGroup 1.06 - Blind SQL Injection
CVE-2010-4916webappswindows07 Sep 2010
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
weborf 0.12.2 - Directory Traversal
CVE-2010-3306remotelinux07 Sep 2010
Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
1024 CMS 2.1.1 - Blind SQL Injection
CVE-2010-1093webappsphp07 Sep 2010
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
ColdBookmarks 1.22 - SQL Injection
CVE-2010-4915webappswindows07 Sep 2010
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Horde Application Framework 3.3.8 - 'icon_browser.php' Cross-Site Scripting
CVE-2010-3077webappsphp06 Sep 2010
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows
23RISK
open
Exploit-DBVexDay Proof
Micronetsoft RV Dealer Website - SQL Injection
CVE-2010-4919webappsasp06 Sep 2010
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbit
23RISK
open
previouspage 182 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.