Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
24,482 exploits
Exploit-DB
PHPBoost 3.0 - Remote Download Backup
CVE-2011-1665webappsphp31 Mar 2011
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISK
open
Exploit-DBVexDay Proof
InTerra Blog Machine 1.84 - 'subject' HTML Injection
CVE-2011-1670webappsphp31 Mar 2011
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RISK
open
Exploit-DBVexDay Proof
Perl 5.x - 'lc()' / 'uc()' TAINT Mode Protection Security Bypass
CVE-2011-1487remotelinux30 Mar 2011
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x
28RISK
open
Exploit-DBVexDay Proof
ICJobSite 1.1 - 'pid' SQL Injection
CVE-2011-1557webappsphp30 Mar 2011
SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
Andy's PHP KnowledgeBase 0.95.2 - 'viewusers.php' SQL Injection
CVE-2011-1546webappsphp30 Mar 2011
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
Andy's PHP KnowledgeBase 0.95.4 - SQL Injection
CVE-2011-1556webappsphp29 Mar 2011
SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote a
23RISK
open
Exploit-DBVexDay Proof
Tracks 1.7.2 - URI Cross-Site Scripting
CVE-2011-1671webappsphp29 Mar 2011
Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel al
23RISK
open
Exploit-DB
WordPress Plugin BackWPup - Remote Code Execution / Local Code Execution
CVE-2011-4342webappsphp28 Mar 2011
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re
28RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 1.1.4 - 'AMV' Dangling Pointer (Metasploit)
CVE-2010-3275remotewindows26 Mar 2011
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe Hostname' CGI Buffer Overflow (Metasploit)
CVE-2010-1555remotewindows25 Mar 2011
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe ICount' CGI Buffer Overflow (Metasploit)
CVE-2010-1554remotewindows24 Mar 2011
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'nnmRptConfig.exe schdParams' Remote Buffer Overflow (Metasploit)
CVE-2011-0267remotewindows24 Mar 2011
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' (MaxAge) CGI Buffer Overflow (Metasploit)
CVE-2010-1553remotewindows24 Mar 2011
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe main' Remote Buffer Overflow (Metasploit)
CVE-2010-1964remotewindows23 Mar 2011
Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
50RISK
open
Exploit-DBVexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe execvp' Remote Buffer Overflow (Metasploit)
CVE-2010-2703remotewindows23 Mar 2011
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM)
60RISK
open
Exploit-DB
Symantec LiveUpdate Administrator Management GUI - HTML Injection
CVE-2011-0545webappswindows23 Mar 2011
Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allo
23RISK
open
Exploit-DBVexDay Proof
Progea Movicon 11 - 'TCPUploadServer' Remote File System
CVE-2011-2963remotewindows23 Mar 2011
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, whi
23RISK
open
Exploit-DBVexDay Proof
Advantech/BroadWin SCADA Webaccess 7.0 - Multiple Vulnerabilities
CVE-2011-4041remotemultiple23 Mar 2011
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code
28RISK
open
Exploit-DBVexDay Proof
Perl 5.x - 'Perl_reg_numbered_buff_fetch()' Remote Denial of Service
CVE-2010-4777dosmultiple23 Mar 2011
The Perl_reg_numbered_buff_fetch function in Perl 5.10.0, 5.12.0, 5.14.0, and other versions, when running with debuggin
23RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe' Unrecognized Option Buffer Overflow (Metasploit)
CVE-2010-1960remotewindows23 Mar 2011
Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.5
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - nnmRptConfig nameParams Buffer Overflow (Metasploit)
CVE-2011-0266remotewindows23 Mar 2011
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe ovutil' Remote Buffer Overflow (Metasploit)
CVE-2010-1961remotewindows23 Mar 2011
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remo
50RISK
open
Exploit-DBVexDay Proof
HP Network Node Manager (NMM) - CGI 'webappmon.exe OvJavaLocale' Remote Buffer Overflow (Metasploit)
CVE-2010-2709remotewindows23 Mar 2011
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'snmpviewer.exe' Remote Buffer Overflow (Metasploit)
CVE-2010-1552remotewindows23 Mar 2011
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01,
50RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - AVM Bytecode Verification (Metasploit)
CVE-2011-0609HIGHunder attackremotewindows23 Mar 2011
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RISK
open
Exploit-DB
Symantec LiveUpdate Administrator Management GUI - HTML Injection
CVE-2011-1524webappswindows23 Mar 2011
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) bef
23RISK
open
Exploit-DB
DATAC RealWin - Multiple Vulnerabilities
CVE-2011-1564doswindows22 Mar 2011
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remo
28RISK
open
Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
CVE-2011-1565remotewindows22 Mar 2011
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RISK
open
Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
CVE-2011-1568remotewindows22 Mar 2011
Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11
28RISK
open
Exploit-DB
7-Technologies IGSS 9.00.00.11059 - Multiple Vulnerabilities
CVE-2011-1566remotewindows22 Mar 2011
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RISK
open
previouspage 326 / 817next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.