Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Audio File Library 0.2.6 - libaudiofile 'msadpcm.c .WAV' File Processing Buffer Overflow
CVE-2008-5824remotelinux30 Dec 2008
Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a
23RISK
open
Exploit-DBVexDay Proof
xterm - DECRQSS Remote Command Execution
CVE-2006-7236remotelinux29 Dec 2008
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, whic
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Media Player 9/10/11 - '.WAV' File Parsing Code Execution
CVE-2008-5745remotewindows29 Dec 2008
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RISK
open
Exploit-DBVexDay Proof
ViArt Shop 3.5 - 'manuals_search.php?manuals_search' Cross-Site Scripting
CVE-2008-6757webappsphp29 Dec 2008
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-1647remotewindows28 Dec 2008
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RISK
open
Exploit-DBVexDay Proof
Miniweb 2.0 - Authentication Bypass
CVE-2008-2197webappsphp28 Dec 2008
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-4584remotewindows28 Dec 2008
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5865webappsphp24 Dec 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5864webappsphp24 Dec 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5875webappsphp24 Dec 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'qdisc_run()' Local Denial of Service
CVE-2008-5713doslinux23 Dec 2008
The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5865webappsphp23 Dec 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5874webappsphp23 Dec 2008
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5864webappsphp23 Dec 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5875webappsphp23 Dec 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2009-2953doswindows23 Dec 2008
Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption)
23RISK
open
Exploit-DBVexDay Proof
QEMU 0.9 / KVM 36/79 - VNC Server Remote Denial of Service
CVE-2008-2382doslinux22 Dec 2008
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
CVE-2008-5864webappsphp21 Dec 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
CVE-2008-5865webappsphp21 Dec 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISK
open
Exploit-DBVexDay Proof
Easysitenetwork Jokes Complete Website - 'joke.php' SQL Injection
CVE-2008-6880webappsphp18 Dec 2008
SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
ESET Smart Security 3.0.672 - 'epfw.sys' Local Privilege Escalation
CVE-2008-5724localwindows18 Dec 2008
The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows loca
23RISK
open
Exploit-DBVexDay Proof
DO-CMS 3.0 - 'p' Multiple SQL Injections
CVE-2008-6019webappsphp18 Dec 2008
SQL injection vulnerability in index.php in EACOMM DO-CMS 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow
CVE-2008-4270localwindows17 Dec 2008
20RISK
open
Exploit-DBVexDay Proof
TinyMCE 2.0.1 - 'menuID' SQL Injection
CVE-2008-6049webappsphp17 Dec 2008
20RISK
open
Exploit-DBVexDay Proof
PHPcksec 0.2 - 'PHPcksec.php' Cross-Site Scripting
CVE-2008-6609webappsphp17 Dec 2008
Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - XML Parsing Buffer Overflow (1)
CVE-2010-1175remotewindows15 Dec 2008
Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified imp
28RISK
open
Exploit-DBVexDay Proof
Injader 2.1.1 - SQL Injection / HTML Injection
CVE-2008-5891webappsphp15 Dec 2008
Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
FLDS 1.2a - 'redir.php' SQL Injection
CVE-2008-5778webappsphp14 Dec 2008
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
ProSysInfo TFTP server TFTPDWIN 0.4.2 - Universal Remote Buffer Overflow
CVE-2006-4948remotewindows14 Dec 2008
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RISK
open
Exploit-DBVexDay Proof
FLDS 1.2a - 'redir.php' SQL Injection
CVE-2008-5779webappsphp14 Dec 2008
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute ar
23RISK
open
previouspage 281 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.