Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
24,482 exploits
Exploit-DBVexDay Proof
McAfee ePolicy Orchestrator / ProtectionPilot - Remote Overflow (Metasploit)
CVE-2006-5156remotewindows_x8620 Sep 2010
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RISK
open
Exploit-DBVexDay Proof
Mozilla Suite/Firefox - InstallVersion->compareTo() Code Execution (Metasploit)
CVE-2005-2265remotewindows20 Sep 2010
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open
Exploit-DBVexDay Proof
Mozilla Suite/Firefox - Navigator Object Code Execution (Metasploit)
CVE-2006-3677remotemultiple20 Sep 2010
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by chang
60RISK
open
Exploit-DBVexDay Proof
Microsoft WINS - Service Memory Overwrite (MS04-045) (Metasploit)
CVE-2004-1080remotewindows20 Sep 2010
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remo
60RISK
open
Exploit-DBVexDay Proof
iPhone MobileMail - LibTIFF Buffer Overflow (Metasploit)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
Apple iPhone MobileSafari LibTIFF - 'email' Remote Buffer Overflow (Metasploit) (2)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
PHP 4 - Unserialize() ZVAL Reference Counter Overflow (Cookie) (Metasploit)
CVE-2007-1286remotemultiple20 Sep 2010
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISK
open
Exploit-DBVexDay Proof
PeaZIP 2.6.1 - Zip Processing Command Injection (Metasploit)
CVE-2009-2261localmultiple20 Sep 2010
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RISK
open
Exploit-DBVexDay Proof
Java 6.19 CMM readMabCurveData - Remote Stack Overflow
CVE-2010-0838remotewindows20 Sep 2010
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and
28RISK
open
Exploit-DBVexDay Proof
Apple iPhone MobileSafari LibTIFF - 'browser' Remote Buffer Overflow (Metasploit) (1)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COM CreateObject Code Execution (MS06-014/MS06-073) (Metasploit)
CVE-2006-0003remotewindows20 Sep 2010
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISK
open
Exploit-DBVexDay Proof
Macrovision Installshield Update Service - ActiveX Unsafe Method (Metasploit)
CVE-2007-5660remotewindows20 Sep 2010
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISK
open
Exploit-DBVexDay Proof
WebSTAR FTP Server - USER Overflow (Metasploit)
CVE-2004-0695remoteosx20 Sep 2010
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
Arugizer Trojan Horse (Energizer DUO) - Code Execution (Metasploit)
CVE-2010-0103remotewindows20 Sep 2010
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISK
open
Exploit-DBVexDay Proof
LightNEasy CMS 3.2.1 - Blind SQL Injection
CVE-2010-4752webappsphp20 Sep 2010
SQL injection vulnerability in LightNEasy.php in LightNEasy 3.2.1, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
Exploit-DBVexDay Proof
BakBone NetVault - Remote Heap Overflow (Metasploit)
CVE-2005-1009remotewindows20 Sep 2010
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open
Exploit-DB
primitive CMS 1.0.9 - Multiple Vulnerabilities
CVE-2010-3483webappsphp20 Sep 2010
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP) (MS07-017) (Metasploit)
CVE-2007-1765remotewindows20 Sep 2010
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Unreal Tournament 2004 (Linux) - 'secure' Remote Overflow (Metasploit)
CVE-2004-0608remotelinux20 Sep 2010
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open
Exploit-DBVexDay Proof
McAfee Visual Trace - ActiveX Control Buffer Overflow (Metasploit)
CVE-2006-6707remotewindows20 Sep 2010
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Ex
50RISK
open
Exploit-DBVexDay Proof
Solaris LPD - Command Execution (Metasploit)
CVE-2001-1583remotesolaris20 Sep 2010
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RISK
open
Exploit-DBVexDay Proof
IBM TPM for OS Deployment 5.1.0.x - 'rembo.exe' Remote Buffer Overflow (Metasploit)
CVE-2007-1868remotewindows20 Sep 2010
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RISK
open
Exploit-DBVexDay Proof
Microsoft Private Communications Transport - Remote Overflow (MS04-011) (Metasploit)
CVE-2003-0719remotewindows20 Sep 2010
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as u
60RISK
open
Exploit-DBVexDay Proof
SmarterMail 7.1.3876 - Directory Traversal
CVE-2010-3486remotewindows19 Sep 2010
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISK
open
Exploit-DBVexDay Proof
BoutikOne 1.0 - SQL Injection
CVE-2010-3479webappsphp19 Sep 2010
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client Browser Plugin - 'call-back-url' Remote Stack Overflow
CVE-2010-1527remotewindows19 Sep 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
Apple QuickTime FLI LinePacket - Remote Code Execution
CVE-2010-0520doswindows18 Sep 2010
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attacker
28RISK
open
Exploit-DBVexDay Proof
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
CVE-2010-4954webappsphp18 Sep 2010
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4927webappsphp18 Sep 2010
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4928webappsphp18 Sep 2010
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISK
open
previouspage 352 / 817next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.