Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Joomla! Component Joostina - SQL Injection
CVE-2010-4929webappsphp22 Sep 2010
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
CVE-2010-4926webappsphp22 Sep 2010
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
CVE-2010-0886remotewindows21 Sep 2010
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 Sep 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISK
open
Exploit-DBVexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
CVE-2010-2961locallinux21 Sep 2010
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
wpQuiz 2.7 - Authentication Bypass
CVE-2010-3608webappsphp21 Sep 2010
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Relay Code Execution (MS08-068) (Metasploit)
CVE-2008-4037remotewindows21 Sep 2010
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest Buffer Overflow (Metasploit)
CVE-2008-0935remotewindows21 Sep 2010
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control 'debug' Remote Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 Sep 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-1248doswindows21 Sep 2010
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-0824doswindows21 Sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute
28RISK
open
Exploit-DBVexDay Proof
ibPhotohost 1.1.2 - SQL Injection
CVE-2010-3601webappsphp21 Sep 2010
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
CVE-2010-4930webappsphp21 Sep 2010
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit)
CVE-2010-1527remotewindows21 Sep 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Shell LNK Code Execution (MS10-046) (Metasploit)
CVE-2010-2568HIGHunder attackremotewindows21 Sep 2010
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISK
open
Exploit-DBVexDay Proof
McAfee ePolicy Orchestrator / ProtectionPilot - Remote Overflow (Metasploit)
CVE-2006-5156remotewindows_x8620 Sep 2010
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RISK
open
Exploit-DBVexDay Proof
TFTPD32 < 2.21 - 'Filename' Remote Buffer Overflow (Metasploit)
CVE-2002-2226remotewindows20 Sep 2010
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISK
open
Exploit-DBVexDay Proof
Microsoft Private Communications Transport - Remote Overflow (MS04-011) (Metasploit)
CVE-2003-0719remotewindows20 Sep 2010
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as u
60RISK
open
Exploit-DBVexDay Proof
Mozilla Suite/Firefox - InstallVersion->compareTo() Code Execution (Metasploit)
CVE-2005-2265remotewindows20 Sep 2010
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open
Exploit-DBVexDay Proof
Mercur MailServer 5.0 - IMAP SP3 SELECT Buffer Overflow (Metasploit)
CVE-2006-1255remotewindows20 Sep 2010
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open
Exploit-DBVexDay Proof
Proxy-Pro Professional GateKeeper 4.7 - GET Overflow (Metasploit)
CVE-2004-0326remotewindows20 Sep 2010
Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET
50RISK
open
Exploit-DBVexDay Proof
IPSwitch IMail IMAP4D - Delete Overflow (Metasploit)
CVE-2004-1520remotewindows20 Sep 2010
Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a lon
60RISK
open
Exploit-DBVexDay Proof
Hummingbird Connectivity 10 SP5 - LPD Buffer Overflow (Metasploit)
CVE-2005-1815remotewindows20 Sep 2010
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of s
50RISK
open
Exploit-DBVexDay Proof
Sun Java - JRE AWT setDiffICM Buffer Overflow (Metasploit)
CVE-2009-3869remotemultiple20 Sep 2010
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment
50RISK
open
Exploit-DBVexDay Proof
PeaZIP 2.6.1 - Zip Processing Command Injection (Metasploit)
CVE-2009-2261localmultiple20 Sep 2010
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RISK
open
Exploit-DBVexDay Proof
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
CVE-2005-0581remotewindows20 Sep 2010
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISK
open
Exploit-DBVexDay Proof
Computer Associates License Server - GETCONFIG Overflow (Metasploit)
CVE-2005-0581remotewindows20 Sep 2010
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISK
open
Exploit-DBVexDay Proof
HP OpenView OmniBack II - Command Execution (Metasploit)
CVE-2001-0311remotemultiple20 Sep 2010
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RISK
open
Exploit-DBVexDay Proof
Apple Safari - Archive Metadata Command Execution (Metasploit)
CVE-2006-0848remoteunix20 Sep 2010
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex
50RISK
open
Exploit-DBVexDay Proof
CA CAM (Windows x86) - 'log_security()' Remote Stack Buffer Overflow (Metasploit)
CVE-2005-2668remotewindows_x8620 Sep 2010
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1
60RISK
open
previouspage 348 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.