Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,183cataloged exploits
37,028CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/order' SQL Injection
CVE-2009-4796webappsphp29 Mar 2009
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RISK
open
Exploit-DBVexDay Proof
iWare CMS 5.0.4 - Multiple SQL Injections
CVE-2006-6446webappsphp29 Mar 2009
SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote a
23RISK
open
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.7.0 - 'NLST' Denial of Service
CVE-2008-5626doswindows27 Mar 2009
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISK
open
Exploit-DBVexDay Proof
freeSSHd 1.2.1 - 'rename' Remote Buffer Overflow (SEH)
CVE-2008-6899remotewindows27 Mar 2009
Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and ex
23RISK
open
Exploit-DBVexDay Proof
Microsoft GdiPlus - EMF GpFont.SetData Integer Overflow (PoC)
CVE-2009-1217doswindows24 Mar 2009
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers
28RISK
open
Exploit-DBVexDay Proof
Jinzora Media Jukebox 2.8 - 'name' Local File Inclusion
CVE-2009-2313webappsphp24 Mar 2009
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu
23RISK
open
Exploit-DBVexDay Proof
Femitter FTP Server 1.x - (Authenticated) Multiple Vulnerabilities
CVE-2008-2032remotewindows24 Mar 2009
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending
23RISK
open
Exploit-DBVexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Universal Overwrite (SEH)
CVE-2004-0964localwindows23 Mar 2009
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RISK
open
Exploit-DBVexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
CVE-2009-4790remotewindows23 Mar 2009
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modif
23RISK
open
Exploit-DBVexDay Proof
Codice CMS 2 - Command Execution (via SQL Injection)
CVE-2009-2309webappsphp23 Mar 2009
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
WBB3 rGallery 1.2.3 - 'UserGallery' Blind SQL Injection
CVE-2009-2311webappsphp23 Mar 2009
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
CVE-2009-4800remotewindows23 Mar 2009
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrar
23RISK
open
Exploit-DBVexDay Proof
X-BLC 0.2.0 - 'get_read.php?section' SQL Injection
CVE-2009-2310webappsphp23 Mar 2009
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RISK
open
Exploit-DBVexDay Proof
ExpressionEngine 1.6 - Avtaar Name HTML Injection
CVE-2009-1070webappsphp22 Mar 2009
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earli
23RISK
open
Exploit-DBVexDay Proof
Racer 0.5.3 Beta 5 - Remote Stack Buffer Overflow
CVE-2007-4370remotewindows20 Mar 2009
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
Xlight FTP Server 3.2 - 'user' SQL Injection
CVE-2009-4795remotemultiple19 Mar 2009
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow rem
23RISK
open
Exploit-DBVexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
CVE-2010-4151webappsphp18 Mar 2009
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
Exploit-DBVexDay Proof
Foxit Reader 3.0 (Build 1301) - PDF Universal Buffer Overflow
CVE-2009-0837localwindows13 Mar 2009
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RISK
open
Exploit-DBVexDay Proof
YAP 1.1.1 - 'index.php' Local File Inclusion
CVE-2009-1038webappsphp13 Mar 2009
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
SlySoft (Multiple Products) - Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
CVE-2009-0824localwindows12 Mar 2009
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.
23RISK
open
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-list_file_gallery.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 Mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-listpages.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 Mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
phpmysport 1.4 - Cross-Site Scripting / SQL Injection
CVE-2010-1109webappsphp12 Mar 2009
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote a
23RISK
open
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-galleries.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 Mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
PostgreSQL 8.3.6 - Conversion Encoding Remote Denial of Service
CVE-2009-0922doslinux11 Mar 2009
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of servi
28RISK
open
Exploit-DBVexDay Proof
CMS WEBjump! - Multiple SQL Injections
CVE-2009-4892webappsphp10 Mar 2009
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
Sun xVM VirtualBox 2.0/2.1 - Local Privilege Escalation
CVE-2009-0876locallinux10 Mar 2009
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain p
23RISK
open
Exploit-DBVexDay Proof
NextApp Echo < 2.1.1 - XML Injection
CVE-2009-5135remotemultiple10 Mar 2009
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RISK
open
Exploit-DBVexDay Proof
IBM System Director Agent 5.20 - CIM Server Privilege Escalation
CVE-2009-0880localwindows10 Mar 2009
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RISK
open
Exploit-DBVexDay Proof
PHORTAIL 1.2.1 - 'poster.php' Multiple HTML Injection Vulnerabilities
CVE-2009-4888webappsphp09 Mar 2009
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web
23RISK
open
previouspage 275 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.