Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Lattice Semiconductor PAC-Designer 6.21 - Symbol Value Buffer Overflow (Metasploit)
CVE-2012-2915localwindows17 Jun 2012
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RISK
open
Exploit-DBVexDay Proof
PHP 5.4.3 - apache_request_headers Function Buffer Overflow (Metasploit)
CVE-2012-2329remotewindows17 Jun 2012
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote at
50RISK
open
Exploit-DBVexDay Proof
MediaWiki 1.x - 'uselang' Cross-Site Scripting
CVE-2012-2698webappsphp17 Jun 2012
Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.1
23RISK
open
Exploit-DBVexDay Proof
Microsoft XML Core Services - MSXML Uninitialized Memory Corruption (MS12-043) (Metasploit)
CVE-2012-1889HIGHunder attackremotewindows16 Jun 2012
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISK
open
Exploit-DB
Wyse - Machine Remote Power Off (Denial of Service) (Metasploit)
CVE-2009-0695doshardware14 Jun 2012
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RISK
open
Exploit-DBVexDay Proof
Myre Real Estate Mobile 2012 - Multiple Vulnerabilities
CVE-2012-4258webappsphp14 Jun 2012
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrar
23RISK
open
Exploit-DB
Adobe Illustrator CS5.5 - Memory Corruption
CVE-2012-0780localmultiple14 Jun 2012
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption)
28RISK
open
Exploit-DB
Wyse - Machine Remote Power Off (Denial of Service) (Metasploit)
CVE-2009-0693doshardware14 Jun 2012
Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) th
28RISK
open
Exploit-DB
ESRI ArcGIS 10.0.x / ArcMap 9 - Arbitrary Code Execution
CVE-2012-1661localwindows14 Jun 2012
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, wh
28RISK
open
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.30 - Remote Format String Write4
CVE-2007-1195remotewindows14 Jun 2012
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Same ID Property Deleted Object Handling Memory Corruption (MS12-037) (Metasploit)
CVE-2012-1875remotewindows14 Jun 2012
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
Juniper Networks Mobility System Software - '/aaa/wba_login.html' Cross-Site Scripting
CVE-2012-1038remotehardware14 Jun 2012
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility
23RISK
open
Exploit-DBVexDay Proof
Apple iTunes 10.6.1.7 - '.m3u' Walking Heap Buffer Overflow (PoC)
CVE-2012-0677dosmultiple13 Jun 2012
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a de
28RISK
open
Exploit-DBVexDay Proof
F5 BIG-IP - SSH Private Key Exposure (Metasploit)
CVE-2012-1493remotehardware13 Jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.0.2.8 - 'ipchange.php' Command Injection (Metasploit)
CVE-2012-0297webappsphp12 Jun 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RISK
open
Exploit-DBVexDay Proof
F5 BIG-IP - Authentication Bypass
CVE-2012-1493remotehardware12 Jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RISK
open
Exploit-DBVexDay Proof
MySQL - Authentication Bypass
CVE-2012-2122remotemultiple12 Jun 2012
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin wp-gpx-map 1.1.21 - Arbitrary File Upload
CVE-2012-6649webappsphp11 Jun 2012
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
28RISK
open
Exploit-DBVexDay Proof
Microsoft Office - ClickOnce Unsafe Object Package Handling (MS12-005) (Metasploit)
CVE-2012-0013localwindows11 Jun 2012
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RISK
open
Exploit-DBVexDay Proof
F5 BIG-IP - Authentication Bypass (PoC)
CVE-2012-1493doshardware11 Jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RISK
open
Exploit-DBVexDay Proof
BMC Identity Management - Cross-Site Request Forgery
CVE-2012-2959webappsjava11 Jun 2012
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite
23RISK
open
Exploit-DBVexDay Proof
Tom Sawyer Software GET Extension Factory - Remote Code Execution (Metasploit)
CVE-2011-2217remotewindows10 Jun 2012
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.0.2.8 - Arbitrary '.PHP' File Upload (Metasploit)
CVE-2012-0299webappsphp10 Jun 2012
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to u
50RISK
open
Exploit-DBVexDay Proof
Microsoft IIS - MDAC 'msadcs.dll' RDS DataStub Content-Type Overflow (MS02-065) (Metasploit)
CVE-2002-1142remotewindows08 Jun 2012
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 th
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin RBX Gallery 2.1 - Arbitrary File Upload
CVE-2012-3575webappsphp08 Jun 2012
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin wpStoreCart 2.5.27-2.5.29 - Arbitrary File Upload
CVE-2012-3576webappsphp08 Jun 2012
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RISK
open
Exploit-DBVexDay Proof
Samsung NET-i viewer - Multiple ActiveX 'BackupToAvi()' Remote Overflows (Metasploit)
CVE-2012-4333remotewindows08 Jun 2012
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin NewsLetter 1.5 - Remote File Disclosure
CVE-2012-3588webappsphp08 Jun 2012
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
Sielco Sistemi Winlog 2.07.14 - Remote Buffer Overflow (Metasploit)
CVE-2012-3815remotewindows08 Jun 2012
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin FCChat Widget 2.2.x - 'upload.php' Arbitrary File Upload
CVE-2012-3578webappsphp07 Jun 2012
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress
23RISK
open
previouspage 281 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.