Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,646cataloged exploits
37,382CVEs with public exploitation
24,695lab-tested
24,482 exploits
Exploit-DBVexDay Proof
Tom Sawyer Software GET Extension Factory - Remote Code Execution (Metasploit)
CVE-2011-2217remotewindows10 Jun 2012
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.0.2.8 - Arbitrary '.PHP' File Upload (Metasploit)
CVE-2012-0299webappsphp10 Jun 2012
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to u
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin wpStoreCart 2.5.27-2.5.29 - Arbitrary File Upload
CVE-2012-3576webappsphp08 Jun 2012
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin NewsLetter 1.5 - Remote File Disclosure
CVE-2012-3588webappsphp08 Jun 2012
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
Sielco Sistemi Winlog 2.07.14 - Remote Buffer Overflow (Metasploit)
CVE-2012-3815remotewindows08 Jun 2012
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin RBX Gallery 2.1 - Arbitrary File Upload
CVE-2012-3575webappsphp08 Jun 2012
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
Microsoft IIS - MDAC 'msadcs.dll' RDS DataStub Content-Type Overflow (MS02-065) (Metasploit)
CVE-2002-1142remotewindows08 Jun 2012
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 th
60RISK
open
Exploit-DBVexDay Proof
Samsung NET-i viewer - Multiple ActiveX 'BackupToAvi()' Remote Overflows (Metasploit)
CVE-2012-4333remotewindows08 Jun 2012
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin FCChat Widget 2.2.x - 'upload.php' Arbitrary File Upload
CVE-2012-3578webappsphp07 Jun 2012
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress
23RISK
open
Exploit-DBVexDay Proof
Lattice Semiconductor PAC-Designer 6.21 - '.PAC' Local Overflow
CVE-2012-2915localwindows07 Jun 2012
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RISK
open
Exploit-DBVexDay Proof
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
CVE-2012-3574webappsphp06 Jun 2012
Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Font Uploader 1.2.4 - Arbitrary File Upload
CVE-2012-3814webappsphp06 Jun 2012
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Object File Handling Remote Code Execution (Metasploit)
CVE-2011-3400remotewindows06 Jun 2012
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RISK
open
Exploit-DBVexDay Proof
Apache Struts 2.2.1.1 - Remote Command Execution (Metasploit)
CVE-2012-0391CRITICALunder attackremotemultiple05 Jun 2012
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RISK
open
Exploit-DBVexDay Proof
Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)
CVE-2011-4825webappsphp03 Jun 2012
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISK
open
Exploit-DBVexDay Proof
GIMP script-fu - Server Buffer Overflow (Metasploit)
CVE-2012-2763remotewindows02 Jun 2012
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RISK
open
Exploit-DB
GIMP 2.6 script-fu < 2.8.0 - Buffer Overflow (PoC)
CVE-2012-2763doswindows31 May 2012
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RISK
open
Exploit-DB
Sony VAIO Wireless Manager 4.0.0.0 - Buffer Overflow
CVE-2012-0985doswindows31 May 2012
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wi
28RISK
open
Exploit-DBVexDay Proof
Simple Web Content Management System 1.1 < 1.3 - Multiple SQL Injections
CVE-2012-3791webappsphp30 May 2012
Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
MPlayer - '.SAMI' Subtitle File Buffer Overflow (Metasploit)
CVE-2011-3625localwindows30 May 2012
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RISK
open
Exploit-DB
WinRadius Server 2009 - Denial of Service
CVE-2012-3816doswindows29 May 2012
WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Requ
23RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.0.2.8 - Command Execution (Metasploit)
CVE-2012-0297remotelinux28 May 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.0.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2012-0297webappslinux26 May 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RISK
open
Exploit-DBVexDay Proof
SocialEngine 4.2.2 - Multiple Vulnerabilities
CVE-2012-2216webappsphp25 May 2012
20RISK
open
Exploit-DBVexDay Proof
appRain CMF - Arbitrary '.PHP' File Upload (Metasploit)
CVE-2012-1153webappsphp25 May 2012
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISK
open
Exploit-DBVexDay Proof
OpenOffice - OLE Importer DocumentSummaryInformation Stream Handling Overflow (Metasploit)
CVE-2008-0320localwindows25 May 2012
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of
50RISK
open
Exploit-DBVexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
CVE-2012-3826dosmultiple24 May 2012
Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a de
23RISK
open
Exploit-DB
Jaow 2.4.5 - Blind SQL Injection
CVE-2012-2952webappsphp24 May 2012
SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
CVE-2012-3825dosmultiple24 May 2012
Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a den
23RISK
open
Exploit-DBVexDay Proof
Wireshark - Misaligned Memory Denial of Service
CVE-2012-2394dosmultiple24 May 2012
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data a
23RISK
open
previouspage 283 / 817next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.