Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Microsoft Office 2010 - '.RTF' Header Stack Overflow
CVE-2010-3333HIGHunder attacklocalwindows03 Jul 2011
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open
Exploit-DB
Microsoft IIS 7.0 FTP Server - Stack Exhaustion Denial of Service (MS09-053) (Metasploit)
CVE-2009-2521doswindows03 Jul 2011
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RISK
open
Exploit-DBVexDay Proof
Adobe Reader X 10.0.0 < 10.0.1 - Atom Type Confusion
CVE-2011-0611HIGHunder attacklocalwindows03 Jul 2011
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISK
open
Exploit-DBVexDay Proof
HP Data Protector 6.11 - Remote Buffer Overflow (DEP Bypass)
CVE-2011-1865remotewindows02 Jul 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open
Exploit-DBVexDay Proof
HP - 'OmniInet.exe' Opcode 27 Buffer Overflow (Metasploit)
CVE-2011-1865remotewindows01 Jul 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open
Exploit-DBVexDay Proof
Joomla! Component mDigg 2.2.8 - SQL Injection
CVE-2008-6149webappsphp01 Jul 2011
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
HP Data Protector 6.20 - EXEC_CMD Buffer Overflow
CVE-2011-1866doswindows30 Jun 2011
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remot
28RISK
open
Exploit-DBVexDay Proof
HP Data Protector 6.20 - Multiple Vulnerabilities
CVE-2011-1865doswindows29 Jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open
Exploit-DBVexDay Proof
Microsoft Visio - 'VISIODWG.dll .DXF' File Handling (MS10-028) (Metasploit)
CVE-2010-1681localwindows26 Jun 2011
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RISK
open
Exploit-DBVexDay Proof
AzeoTech DaqFactory - Denial of Service
CVE-2011-2956dosmultiple24 Jun 2011
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote at
23RISK
open
Exploit-DBVexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
CVE-2011-2757webappsjsp23 Jun 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISK
open
Exploit-DBVexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
CVE-2011-2755webappsjsp23 Jun 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RISK
open
Exploit-DBVexDay Proof
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
CVE-2011-1213remotewindows23 Jun 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISK
open
Exploit-DBVexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
CVE-2011-2755webappsjsp23 Jun 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RISK
open
Exploit-DBVexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
CVE-2011-2757webappsjsp23 Jun 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISK
open
Exploit-DBVexDay Proof
Sielco Sistemi Winlog - Remote Buffer Overflow (Metasploit)
CVE-2011-0517remotewindows21 Jun 2011
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISK
open
Exploit-DBVexDay Proof
Black Ice Cover Page - ActiveX Control Arbitrary File Download (Metasploit)
CVE-2008-2683remotewindows21 Jun 2011
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open
Exploit-DBVexDay Proof
DreamBox DM800 - Arbitrary File Download
CVE-2011-4716remotehardware21 Jun 2011
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (2)
CVE-2011-0073remotewindows20 Jun 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RISK
open
Exploit-DBVexDay Proof
Black Ice Cover Page SDK - Insecure Method 'DownloadImageFileURL()' (Metasploit)
CVE-2008-2683remotewindows20 Jun 2011
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open
Exploit-DBVexDay Proof
Cisco Unified Operations Manager 8.5 - 'iptm/advancedfind.do?extn' Cross-Site Scripting
CVE-2011-0959remotehardware18 Jun 2011
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RISK
open
Exploit-DBVexDay Proof
Cisco Unified Operations Manager 8.5 - iptm/eventmon Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-0959remotehardware18 Jun 2011
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RISK
open
Exploit-DBVexDay Proof
Cisco Unified Operations Manager 8.5 - 'iptm/ddv.do?deviceInstanceName' Cross-Site Scripting
CVE-2011-0959remotehardware18 Jun 2011
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RISK
open
Exploit-DBVexDay Proof
Cisco Unified Operations Manager 8.5 - '/iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-0959remotehardware18 Jun 2011
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RISK
open
Exploit-DBVexDay Proof
Cisco Unified Operations Manager 8.5 - '/iptm/logicalTopo.do' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-0959remotehardware18 Jun 2011
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML!CObjectElement Use-After-Free (MS11-050) (Metasploit)
CVE-2011-1260remotewindows17 Jun 2011
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RISK
open
Exploit-DBVexDay Proof
Sunway ForceControl 6.1 - Multiple Heap Buffer Overflow Vulnerabilities
CVE-2011-2960remotewindows17 Jun 2011
Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers t
28RISK
open
Exploit-DBVexDay Proof
Wireshark 1.4.5 - 'bytes_repr_len()' Null Pointer Dereference Denial of Service
CVE-2011-1956doswindows17 Jun 2011
The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to caus
23RISK
open
Exploit-DBVexDay Proof
IBM Websphere Application Server 7.0.0.13 - Cross-Site Request Forgery
CVE-2010-3271webappsmultiple15 Jun 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative conso
23RISK
open
Exploit-DBVexDay Proof
Opera Web Browser 11.11 - Remote Crash
CVE-2011-2641doswindows14 Jun 2011
Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a
23RISK
open
previouspage 321 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.