Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
CVE-2010-5240localwindows25 Aug 2010
Multiple untrusted search path vulnerabilities in Corel PHOTO-PAINT and CorelDRAW X5 15.1.0.588 allow local users to gai
23RISK
open
Exploit-DBVexDay Proof
Autodesk AutoCAD 2007 - 'color.dll' DLL Hijacking
CVE-2010-5241localwindows25 Aug 2010
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Troja
23RISK
open
Exploit-DBVexDay Proof
Adobe Extension Manager CS5 5.0.298 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3154localwindows25 Aug 2010
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attac
28RISK
open
Exploit-DBVexDay Proof
Eureka Email Client 2.2q - ERR Remote Buffer Overflow (Metasploit) (2)
CVE-2009-3837remotewindows25 Aug 2010
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RISK
open
Exploit-DBVexDay Proof
Google Earth 5.1.3535.3218 - 'quserex.dll' DLL Hijacking
CVE-2010-3134localwindows25 Aug 2010
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RISK
open
Exploit-DBVexDay Proof
μTorrent (uTorrent) 2.0.3 - DLL Hijacking
CVE-2010-3129localwindows25 Aug 2010
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RISK
open
Exploit-DBVexDay Proof
SquirrelMail PGP Plugin - Command Execution (SMTP) (Metasploit)
CVE-2003-0990remotelinux25 Aug 2010
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RISK
open
Exploit-DBVexDay Proof
Mercur Messaging 2005 - IMAP Login Buffer Overflow (Metasploit)
CVE-2006-1255remotewindows25 Aug 2010
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open
Exploit-DBVexDay Proof
TechSmith Snagit 10 (Build 788) - 'dwmapi.dll' DLL Hijacking
CVE-2010-3130localwindows25 Aug 2010
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remo
23RISK
open
Exploit-DBVexDay Proof
μTorrent (uTorrent) 2.0.3 - 'plugin_dll.dll' DLL Hijacking
CVE-2010-3129localwindows24 Aug 2010
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.6.8 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3131localwindows24 Aug 2010
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open
Exploit-DBVexDay Proof
Opera 10.61 - 'dwmapi.dll' DLL Hijacking
CVE-2010-5227localwindows24 Aug 2010
Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmap
23RISK
open
Exploit-DBVexDay Proof
Wireshark 1.2.10 - 'airpcap.dll' DLL Hijacking
CVE-2010-3133localwindows24 Aug 2010
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and p
23RISK
open
Exploit-DBVexDay Proof
MicroP 0.1.1.1600 - 'mppl' Local Buffer Overflow
CVE-2010-5299localwindows23 Aug 2010
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RISK
open
Exploit-DBVexDay Proof
Auto CMS 1.6 - 'autocms.php' Cross-Site Scripting
CVE-2010-4882webappsphp23 Aug 2010
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
MySQL 5.1.48 - 'EXPLAIN' Denial of Service
CVE-2010-3682doslinux20 Aug 2010
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mys
28RISK
open
Exploit-DBVexDay Proof
Oracle MySQL < 5.1.49 - Malformed 'BINLOG' Arguments Denial of Service
CVE-2010-3679doslinux20 Aug 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via
28RISK
open
Exploit-DBVexDay Proof
OraclMySQL 5.1.48 - 'LOAD DATA INFILE' Denial of Service
CVE-2010-3683doslinux20 Aug 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL err
28RISK
open
Exploit-DBVexDay Proof
Oracle MySQL 5.1.48 - 'HANDLER' Interface Denial of Service
CVE-2010-3681doslinux20 Aug 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysq
28RISK
open
Exploit-DBVexDay Proof
MySQL 5.1.48 - 'Temporary InnoDB' Tables Denial of Service
CVE-2010-3680dosphp19 Aug 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by c
28RISK
open
Exploit-DBVexDay Proof
FreeBSD - 'mbufs()' sendfile Cache Poisoning Privilege Escalation
CVE-2010-2693localfreebsd19 Aug 2010
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, whi
23RISK
open
Exploit-DBVexDay Proof
Cacti 0.8.7 (RedHat High Performance Computing [HPC]) - 'utilities.php?Filter' Cross-Site Scripting
CVE-2010-2544webappsphp19 Aug 2010
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Co
23RISK
open
Exploit-DBVexDay Proof
Flock Browser 3.0.0 - Malformed Bookmark HTML Injection
CVE-2010-3202remotemultiple19 Aug 2010
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)
CVE-2007-2447remoteunix18 Aug 2010
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
Exploit-DBVexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
CVE-2010-3307webappsphp17 Aug 2010
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow
23RISK
open
Exploit-DBVexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
CVE-2010-3742webappsphp17 Aug 2010
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attac
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - KTM Invalid Free with Reused Transaction GUID (MS10-047)
CVE-2010-1889HIGHdoswindows17 Aug 2010
Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, al
41RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - nt!SeObjectCreateSaclAccessBits() Missed ACE Bounds Checks (MS10-047)
CVE-2010-1890doswindows17 Aug 2010
The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properl
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - nt!NtCreateThread Race Condition with Invalid Code Segment (MS10-047)
CVE-2010-1888doswindows17 Aug 2010
Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thr
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Win32k!GreStretchBltInternal() Does Not Handle src == dest
CVE-2010-1887doswindows17 Aug 2010
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RISK
open
previouspage 185 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.