Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,183cataloged exploits
37,028CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2008-6126webappsphp10 Apr 2009
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary fi
23RISK
open
Exploit-DBVexDay Proof
w3bcms Gaestebuch 3.0.0 - Blind SQL Injection
CVE-2009-2337webappsphp10 Apr 2009
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag
23RISK
open
Exploit-DBVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-4209webappsphp10 Apr 2009
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
Cisco Subscriber Edge Services Manager - Cross-Site Scripting / HTML Injection
CVE-2009-1287webappsjava09 Apr 2009
Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inj
28RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Advanced Management Module 1.42 - Login 'Username' Cross-Site Scripting
CVE-2009-1288webappsmultiple09 Apr 2009
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, incl
23RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Advanced Management Module 1.42 - Cross-Site Request Forgery
CVE-2009-1290webappsmultiple09 Apr 2009
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Managemen
23RISK
open
Exploit-DBVexDay Proof
IBM Bladecenter Advanced Management Module 1.42 - '/private/file_Management.ssi?PATH' Cross-Site Scripting
CVE-2009-1288webappsmultiple09 Apr 2009
Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, incl
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 2.6.29 - 'exit_notify()' Local Privilege Escalation
CVE-2009-1337locallinux08 Apr 2009
The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the
23RISK
open
Exploit-DBVexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
CVE-2009-0534webappsphp06 Apr 2009
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter
23RISK
open
Exploit-DBVexDay Proof
ActiveKB KnowledgeBase - 'Panel' Local File Inclusion
CVE-2009-4957webappsphp03 Apr 2009
Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary file
23RISK
open
Exploit-DBVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1281webappsphp03 Apr 2009
Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / (Authenticated) Code Execution
CVE-2008-2996webappsphp03 Apr 2009
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled
23RISK
open
Exploit-DBVexDay Proof
IBM DB2 < 9.5 pack 3a - Connect Denial of Service
CVE-2009-0172dosmultiple03 Apr 2009
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cau
23RISK
open
Exploit-DBVexDay Proof
BlogEngine.NET 1.4 - 'search.aspx' Cross-Site Scripting
CVE-2008-6476webappsasp01 Apr 2009
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
Oracle WebLogic IIS connector JSESSIONID - Remote Overflow
CVE-2008-5457remotewindows01 Apr 2009
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA
50RISK
open
Exploit-DBVexDay Proof
PHPRecipeBook 2.39 - 'course_id' SQL Injection
CVE-2009-4883webappsphp31 Mar 2009
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Sun Java System Calendar Server 6.3 - Duplicate URI Request Denial of Service
CVE-2009-1219dosjava31 Mar 2009
Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-
23RISK
open
Exploit-DBVexDay Proof
Sun Java System Calendar Server 6 - 'command.shtml' Cross-Site Scripting
CVE-2009-1218webappsjava31 Mar 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an
23RISK
open
Exploit-DBVexDay Proof
Turnkey eBook Store 1.1 - 'keywords' Cross-Site Scripting
CVE-2009-1225webappsphp31 Mar 2009
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit
23RISK
open
Exploit-DBVexDay Proof
Cisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site Scripting
CVE-2009-1220remotehardware31 Mar 2009
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA
23RISK
open
Exploit-DBVexDay Proof
Community CMS 0.5 - Multiple SQL Injections
CVE-2009-4794webappsphp31 Mar 2009
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-4475remotewindows31 Mar 2009
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RISK
open
Exploit-DBVexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
CVE-2009-4798webappsasp30 Mar 2009
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
JobHut 1.2 - 'pk' SQL Injection
CVE-2009-4797webappsphp30 Mar 2009
SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
CVE-2009-4799webappsasp30 Mar 2009
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att
23RISK
open
Exploit-DBVexDay Proof
family connection 1.8.1 - Multiple Vulnerabilities
CVE-2009-4791webappsphp30 Mar 2009
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
CVE-2009-4792webappsphp30 Mar 2009
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
CVE-2009-4793webappsphp30 Mar 2009
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authentic
23RISK
open
Exploit-DBVexDay Proof
AtomixMP3 < 2.3 - 'Playlist' Universal Overwrite (SEH)
CVE-2007-4803localwindows30 Mar 2009
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RISK
open
Exploit-DBVexDay Proof
pam-krb5 < 3.13 - Local Privilege Escalation
CVE-2009-0360locallinux29 Mar 2009
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries
23RISK
open
previouspage 274 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.