Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities
CVE-2011-5195webappsphp23 Dec 2011
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference
23RISK
open
Exploit-DBVexDay Proof
Open Conference/Journal/Harvester Systems 2.3.x - Multiple Remote Code Execution Vulnerabilities
CVE-2011-5196webappsphp23 Dec 2011
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Sys
23RISK
open
Exploit-DB
Tiki Wiki CMS Groupware 8.2 - 'snarf_ajax.php' Remote PHP Code Injection
CVE-2011-4558webappsphp22 Dec 2011
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and re
23RISK
open
Exploit-DBVexDay Proof
SpamTitan 5.08 - Multiple Vulnerabilities
CVE-2011-5149webappsphp21 Dec 2011
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.08 and earlier allow remote attackers to inject arbit
23RISK
open
Exploit-DBVexDay Proof
SpamTitan 5.08 - Multiple Vulnerabilities
CVE-2011-5150webappsphp21 Dec 2011
Multiple cross-site scripting (XSS) vulnerabilities in SpamTitan 5.07 and possibly earlier allow remote attackers or aut
23RISK
open
Exploit-DBVexDay Proof
Plone and Zope - Remote Command Execution
CVE-2011-3587webappsmultiple21 Dec 2011
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISK
open
Exploit-DB
Infoproject Business Hero - Multiple Vulnerabilities
CVE-2011-5040webappsphp21 Dec 2011
Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitra
23RISK
open
Exploit-DB
Infoproject Business Hero - Multiple Vulnerabilities
CVE-2011-5039webappsphp21 Dec 2011
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
IrfanView FlashPix PlugIn - Double-Free
CVE-2011-5232doswindows20 Dec 2011
20RISK
open
Exploit-DBVexDay Proof
IrfanView FlashPix PlugIn - Double-Free
CVE-2012-0025doswindows20 Dec 2011
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the Fla
23RISK
open
Exploit-DBVexDay Proof
TORCS 1.3.1 - acc Buffer Overflow
CVE-2011-4620localwindows20 Dec 2011
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products,
28RISK
open
Exploit-DBVexDay Proof
Cyberoam UTM 10 - 'tableid' SQL Injection
CVE-2011-5050webappsphp20 Dec 2011
SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allo
23RISK
open
Exploit-DBVexDay Proof
Tiki Wiki CMS Groupware 8.1 - 'show_errors' HTML Injection
CVE-2011-4551webappsphp20 Dec 2011
Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5
23RISK
open
Exploit-DBVexDay Proof
IrfanView - '.tiff' Image Processing Buffer Overflow
CVE-2011-5233doswindows20 Dec 2011
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows
23RISK
open
Exploit-DB
appRain CMF 0.1.5 - Multiple Web Vulnerabilities
CVE-2011-5229webappsphp19 Dec 2011
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attac
23RISK
open
Exploit-DB
Free Mp3 Player 1.0 - Local Denial of Service
CVE-2011-5043doswindows19 Dec 2011
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long strin
23RISK
open
Exploit-DBVexDay Proof
DotA OpenStats 1.3.9 - SQL Injection
CVE-2011-5218webappsphp19 Dec 2011
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DB
appRain CMF 0.1.5 - Multiple Web Vulnerabilities
CVE-2011-5228webappsphp19 Dec 2011
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att
23RISK
open
Exploit-DBVexDay Proof
PHP Booking Calendar 10e - 'page_info_message' Cross-Site Scripting
CVE-2011-5045webappsphp19 Dec 2011
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inje
23RISK
open
Exploit-DBVexDay Proof
PHP 5.3.8 - Remote Denial of Service
CVE-2012-0789dosphp18 Dec 2011
Memory leak in the timezone functionality in PHP before 5.3.9 allows remote attackers to cause a denial of service (memo
23RISK
open
Exploit-DB
novell sentinel log manager 1.2.0.1 - Directory Traversal
CVE-2011-5028webappsmultiple18 Dec 2011
Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlie
23RISK
open
Exploit-DBVexDay Proof
Apple Safari - GdiDrawStream Blue Screen of Death
CVE-2011-5046doswindows_x86-6418 Dec 2011
The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Window
35RISK
open
Exploit-DBVexDay Proof
Flirt-Projekt 4.8 - 'rub' SQL Injection
CVE-2011-5222webappsphp17 Dec 2011
SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execu
23RISK
open
Exploit-DBVexDay Proof
Capexweb 1.1 - SQL Injection
CVE-2011-5031webappsmultiple16 Dec 2011
Multiple SQL injection vulnerabilities in servlet/capexweb.parentvalidatepassword in cApexWEB 1.1 allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
Seotoaster - SQL Injection
CVE-2011-5230webappsphp16 Dec 2011
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log
23RISK
open
Exploit-DB
mPDF 5.3 - File Disclosure
CVE-2011-5219webappsphp16 Dec 2011
Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbi
23RISK
open
Exploit-DBVexDay Proof
Splunk - Remote Command Execution
CVE-2011-4779remotemultiple15 Dec 2011
20RISK
open
Exploit-DBVexDay Proof
Splunk - Remote Command Execution
CVE-2011-4643remotemultiple15 Dec 2011
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitra
23RISK
open
Exploit-DBVexDay Proof
Splunk - Remote Command Execution
CVE-2011-4644remotemultiple15 Dec 2011
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an envir
23RISK
open
Exploit-DBVexDay Proof
Splunk - Remote Command Execution
CVE-2011-4642remotemultiple15 Dec 2011
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISK
open
previouspage 306 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.