Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Seagull 0.6.7 - SQL Injection
CVE-2010-3212webappsphp29 Aug 2010
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
GaleriaSHQIP 1.0 - SQL Injection
CVE-2010-3207webappsphp28 Aug 2010
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
XOOPS 2.0.14 - 'article.php' SQL Injection
CVE-2008-2094webappsphp28 Aug 2010
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
iGaming CMS - Multiple SQL Injections
CVE-2008-5841webappsphp27 Aug 2010
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc1 (Ubuntu 10.04 / 2.6.32) - 'CAN BCM' Local Privilege Escalation
CVE-2010-2959locallinux27 Aug 2010
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.
23RISK
open
Exploit-DBVexDay Proof
kontakt formular 1.1 - Remote File Inclusion
CVE-2010-4878webappsphp26 Aug 2010
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
Gaestebuch 1.2 - Remote File Inclusion
CVE-2010-4884webappsphp26 Aug 2010
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
EncFS 1.6.0 - Flawed CBC/CFB Cryptography Implementation
CVE-2010-3073locallinux26 Aug 2010
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for
23RISK
open
Exploit-DBVexDay Proof
Google Earth 5.1.3535.3218 - 'quserex.dll' DLL Hijacking
CVE-2010-3134localwindows25 Aug 2010
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RISK
open
Exploit-DBVexDay Proof
Adobe Extension Manager CS5 5.0.298 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3154localwindows25 Aug 2010
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attac
28RISK
open
Exploit-DBVexDay Proof
Xitami Web Server 2.5c2 - If-Modified-Since Overflow (Metasploit)
CVE-2007-5067remotewindows25 Aug 2010
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RISK
open
Exploit-DBVexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
CVE-2010-5240localwindows25 Aug 2010
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open
Exploit-DBVexDay Proof
Autodesk AutoCAD 2007 - 'color.dll' DLL Hijacking
CVE-2010-5241localwindows25 Aug 2010
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Troja
23RISK
open
Exploit-DBVexDay Proof
Adobe ExtendedScript Toolkit CS5 3.5.0.52 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3155localwindows25 Aug 2010
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RISK
open
Exploit-DBVexDay Proof
Eureka Email Client 2.2q - ERR Remote Buffer Overflow (Metasploit) (2)
CVE-2009-3837remotewindows25 Aug 2010
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RISK
open
Exploit-DBVexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
CVE-2014-8393localwindows25 Aug 2010
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Internet Communication Settings - 'schannel.dll' DLL Hijacking
CVE-2010-3140localwindows25 Aug 2010
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local
28RISK
open
Exploit-DBVexDay Proof
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
CVE-2010-3147localwindows25 Aug 2010
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Contacts 'wab32res.dll' DLL Hijacking
CVE-2010-3143localwindows25 Aug 2010
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Contacts 'wab32res.dll' DLL Hijacking
CVE-2010-3147localwindows25 Aug 2010
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP
28RISK
open
Exploit-DBVexDay Proof
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
CVE-2010-3143localwindows25 Aug 2010
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISK
open
Exploit-DBVexDay Proof
NullSoft Winamp 5.581 - 'wnaspi32.dll' DLL Hijacking
CVE-2010-3137localwindows25 Aug 2010
Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possi
23RISK
open
Exploit-DBVexDay Proof
Mozilla Thunderbird - 'dwmapi.dll' DLL Hijacking
CVE-2010-3131localwindows25 Aug 2010
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open
Exploit-DBVexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
CVE-2014-8393localwindows25 Aug 2010
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open
Exploit-DBVexDay Proof
SquirrelMail PGP Plugin - Command Execution (SMTP) (Metasploit)
CVE-2003-0990remotelinux25 Aug 2010
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Object Type (MS03-020) (Metasploit)
CVE-2003-0344remotewindows25 Aug 2010
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RISK
open
Exploit-DBVexDay Proof
httpdx - 'tolog()' Format String (Metasploit) (2)
CVE-2009-4769remotewindows25 Aug 2010
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISK
open
Exploit-DBVexDay Proof
httpdx - 'tolog()' Format String (Metasploit) (1)
CVE-2009-4769remotewindows25 Aug 2010
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISK
open
Exploit-DBVexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
CVE-2010-5240localwindows25 Aug 2010
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open
Exploit-DBVexDay Proof
Microsoft Group Convertor - 'imm.dll' DLL Hijacking
CVE-2010-3139localwindows25 Aug 2010
Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and p
28RISK
open
previouspage 184 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.