Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Apache (Windows x86) - Chunked Encoding (Metasploit)
CVE-2002-0392remotewindows_x8607 Jul 2010
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RISK
open
Exploit-DBVexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
CVE-2010-2697webappsphp07 Jul 2010
Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
CVE-2010-2696webappsphp07 Jul 2010
SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
Simple Document Management System - SQL Injection
CVE-2010-4986webappsphp07 Jul 2010
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
Alt-N SecurityGateway 1.0.1 - 'Username' Remote Buffer Overflow (Metasploit)
CVE-2008-4193remotewindows07 Jul 2010
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t
60RISK
open
Exploit-DBVexDay Proof
Sijio Community Software - SQL Injection / Persistent Cross-Site Scripting
CVE-2010-2698webappsphp07 Jul 2010
Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inje
23RISK
open
Exploit-DBVexDay Proof
Lyrics 3.0 - Engine SQL Injection
CVE-2010-2721webappsphp06 Jul 2010
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
BS Business Directory - 'articlesdetails.php' SQL Injection
CVE-2010-4969webappsphp06 Jul 2010
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
CVE-2010-2656webappsphp06 Jul 2010
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before
23RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
CVE-2010-2655webappsphp06 Jul 2010
Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component AutarTimonial 1.0.8 - SQL Injection
CVE-2010-5003webappsphp06 Jul 2010
SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX EvoCam Web Server (Snow Leopard) - ROP Remote Overflow
CVE-2010-2309remoteosx06 Jul 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
CVE-2010-2654webappsphp06 Jul 2010
Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmwar
23RISK
open
Exploit-DBVexDay Proof
Bs Recipes_Website Script - SQL Injection / Authentication Bypass
CVE-2010-2670webappsphp05 Jul 2010
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Orbis CMS 1.0.2 - 'editor-body.php' Cross-Site Scripting
CVE-2010-2669webappsphp05 Jul 2010
Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
WikiWebHelp 0.28 - SQL Injection
CVE-2010-4970webappsphp05 Jul 2010
SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Canteen 1.0 - Local File Inclusion
CVE-2010-4977webappsphp05 Jul 2010
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers t
43RISK
open
Exploit-DBVexDay Proof
NewsOffice 2.0.18 - 'news_show.php' Cross-Site Scripting
CVE-2010-2844webappsphp05 Jul 2010
Cross-site scripting (XSS) vulnerability in news_show.php in Newanz NewsOffice 2.0.18 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
TCW PHP Album - Multiple Vulnerabilities
CVE-2010-2715webappsphp04 Jul 2010
Cross-site scripting (XSS) vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
TCW PHP Album - Multiple Vulnerabilities
CVE-2010-2714webappsphp04 Jul 2010
SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Esoftpro Online Photo Pro 2 - Multiple Vulnerabilities
CVE-2010-4999webappsphp04 Jul 2010
SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary S
23RISK
open
Exploit-DBVexDay Proof
freeFTPd 1.0 - 'Username' Remote Overflow (Metasploit)
CVE-2005-3683remotewindows03 Jul 2010
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISK
open
Exploit-DBVexDay Proof
QuickTime Streaming Server - 'parse_xml.cgi' Remote Execution (Metasploit)
CVE-2003-0050webappscgi03 Jul 2010
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote a
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050) (Metasploit)
CVE-2009-3103remotewindows03 Jul 2010
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
Exploit-DBVexDay Proof
Snort Back Orifice - Pre-Preprocessor Remote (Metasploit)
CVE-2005-3252remotelinux03 Jul 2010
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open
Exploit-DBVexDay Proof
The Matt Wright Guestbook.pl - Arbitrary Command Execution (Metasploit)
CVE-1999-1053webappscgi03 Jul 2010
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RISK
open
Exploit-DBVexDay Proof
WordPress Core 1.5.1.3 - 'cache_lastpostdate' Arbitrary Code Execution (Metasploit)
CVE-2005-2612webappsphp03 Jul 2010
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co
50RISK
open
Exploit-DBVexDay Proof
Borland Interbase - 'INET_connect()' Remote Buffer Overflow (Metasploit)
CVE-2007-5243remotelinux03 Jul 2010
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open
Exploit-DBVexDay Proof
TWiki History TWikiUsers - 'rev' Command Execution (Metasploit)
CVE-2005-2877webappsphp03 Jul 2010
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISK
open
Exploit-DBVexDay Proof
Firebird Relational Database - 'isc_attach_database()' Remote Buffer Overflow (Metasploit)
CVE-2007-5243remotewindows03 Jul 2010
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open
previouspage 191 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.