Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Ero Auktion 2010 - 'news.php' SQL Injection
CVE-2010-0723webappsphp22 Feb 2010
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
TimeClock 0.99 - Cross-Site Request Forgery (Add Admin)
CVE-2010-0707webappsphp20 Feb 2010
Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attack
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion
CVE-2010-1081webappsphp19 Feb 2010
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for
43RISK
open
Exploit-DBVexDay Proof
WSC CMS - Authentication Bypass
CVE-2010-0698webappsphp19 Feb 2010
SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Joomla! Plugin Core Design Scriptegrator - Local File Inclusion
CVE-2010-0759webappsphp18 Feb 2010
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RISK
open
Exploit-DBVexDay Proof
Subex Nikira Fraud Management System GUI - 'message' Cross-Site Scripting
CVE-2010-0706webappsphp18 Feb 2010
Cross-site scripting (XSS) vulnerability in the login/prompt component in Subex Nikira Fraud Management System allows re
23RISK
open
Exploit-DBVexDay Proof
XlentProjects SphereCMS 1.1 - 'archive.php' SQL Injection
CVE-2010-1078webappsphp18 Feb 2010
SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Joomla! Plugin Core Design Scriptegrator - Local File Inclusion
CVE-2010-0760webappsphp18 Feb 2010
Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote atta
23RISK
open
Exploit-DBVexDay Proof
PortWise SSL VPN 4.6 - 'reloadFrame' Cross-Site Scripting
CVE-2010-0703remotemultiple18 Feb 2010
Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Auktionshaus Gelb 3 - 'news.php' SQL Injection
CVE-2010-0721webappsphp17 Feb 2010
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
Erotik Auktionshaus - 'news.php' SQL Injection
CVE-2010-0720webappsphp17 Feb 2010
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Symantec (Multiple Products) - Client Proxy ActiveX 'CLIproxy.dll' Remote Overflow
CVE-2010-0108remotewindows17 Feb 2010
Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVi
28RISK
open
Exploit-DBVexDay Proof
Apple iTunes 9.0.1 - '.pls' Handling Buffer Overflow
CVE-2009-2817localmultiple17 Feb 2010
Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
Pogodny CMS - SQL Injection
CVE-2010-0671webappsphp16 Feb 2010
SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
BGSvetionik BGS CMS - 'search' Cross-Site Scripting
CVE-2010-0675webappsphp16 Feb 2010
Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Copperleaf Photolog 0.16 - SQL Injection
CVE-2010-0673webappsphp15 Feb 2010
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RISK
open
Exploit-DBVexDay Proof
Alt-N WebAdmin - USER Buffer Overflow (Metasploit)
CVE-2003-0471remotewindows15 Feb 2010
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISK
open
Exploit-DBVexDay Proof
Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit)
CVE-2006-3747remotewindows15 Feb 2010
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open
Exploit-DBVexDay Proof
JTL-Shop 2 - 'druckansicht.php' SQL Injection
CVE-2010-0691webappsphp14 Feb 2010
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
CVE-2010-0678webappsphp14 Feb 2010
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open
Exploit-DBVexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
CVE-2010-0677webappsphp14 Feb 2010
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.9 - Failure to Restrict URL Access
CVE-2010-0682webappsphp13 Feb 2010
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request
23RISK
open
Exploit-DBVexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
CVE-2010-0674webappsphp13 Feb 2010
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Exploit-DBVexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
CVE-2010-0681webappsphp13 Feb 2010
ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open
Exploit-DBVexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
CVE-2010-0680webappsphp13 Feb 2010
Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary l
23RISK
open
Exploit-DBVexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
CVE-2008-0843webappsphp13 Feb 2010
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISK
open
Exploit-DBVexDay Proof
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
CVE-2004-2086remotewindows13 Feb 2010
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RISK
open
Exploit-DBVexDay Proof
WSN Guest 1.02 - 'orderlinks' SQL Injection
CVE-2010-0672webappsphp13 Feb 2010
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
Basic-CMS - 'nav_id' Cross-Site Scripting
CVE-2010-0695webappsphp12 Feb 2010
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Vacation Rental Script - SQL Injection
CVE-2010-0763webappsphp11 Feb 2010
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute
23RISK
open
previouspage 219 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.