Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
JE Ajax Event Calendar - Local File Inclusion
CVE-2010-2129webappsphp14 May 2010
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion
CVE-2010-2128webappsphp14 May 2010
Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote a
43RISK
open
Exploit-DBVexDay Proof
Symantec Alert Management System Intel Alert Originator Service - Remote Buffer Overflow (Metasploit)
CVE-2009-1430remotewindows13 May 2010
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RISK
open
Exploit-DBVexDay Proof
Joomla! Component Komento 1.0.0 - 'sid' SQL Injection
CVE-2010-2044webappsphp13 May 2010
SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion
CVE-2010-2045webappsphp13 May 2010
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISK
open
Exploit-DBVexDay Proof
TomatoCMS 2.0.x - SQL Injection
CVE-2010-1994webappsphp12 May 2010
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Adobe Shockwave Player 11.5.6.606 - 'DIR' Multiple Memory Vulnerabilities
CVE-2010-1280doswindows12 May 2010
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open
Exploit-DBVexDay Proof
Apple Safari 4.0.5 - 'parent.close()' Memory Corruption Code Execution
CVE-2010-1939remotewindows11 May 2010
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
CVE-2010-0816doswindows11 May 2010
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2
28RISK
open
Exploit-DBVexDay Proof
Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting
CVE-2010-1997webappsphp11 May 2010
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "
23RISK
open
Exploit-DBVexDay Proof
AgentX++ Master - AgentX::receive_agentx Stack Buffer Overflow (Metasploit)
CVE-2010-1318remotewindows11 May 2010
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RISK
open
Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
CVE-2008-1909webappsphp10 May 2010
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
724CMS Enterprise 4.59 - SQL Injection
CVE-2008-1858webappsphp10 May 2010
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
tekno.Portal 0.1b - 'makale.php?id' SQL Injection
CVE-2010-1925webappsphp10 May 2010
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting
CVE-2010-2003webappsphp10 May 2010
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject a
23RISK
open
Exploit-DB
29o3 CMS - 'LibDir' Multiple Remote File Inclusions
CVE-2010-1922webappsphp10 May 2010
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
CVE-2008-5088webappsphp10 May 2010
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execu
23RISK
open
Exploit-DBVexDay Proof
DATAC RealWin SCADA Server - Remote Buffer Overflow (Metasploit)
CVE-2008-4322remotewindows09 May 2010
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att
50RISK
open
Exploit-DBVexDay Proof
iseemedia / Roxio / MGI Software LPViewer - ActiveX Control Buffer Overflow (Metasploit)
CVE-2008-4384remotewindows09 May 2010
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISK
open
Exploit-DBVexDay Proof
Creative Software AutoUpdate Engine - ActiveX Control Buffer Overflow (Metasploit)
CVE-2008-0955remotewindows09 May 2010
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISK
open
Exploit-DBVexDay Proof
Winamp Ultravox Streaming Metadata 'in_mp3.dll' - Remote Buffer Overflow (Metasploit)
CVE-2008-0065remotewindows09 May 2010
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbi
50RISK
open
Exploit-DBVexDay Proof
freeFTPd 1.0.10 - Key Exchange Algorithm String Buffer Overflow (Metasploit)
CVE-2006-2407remotewindows09 May 2010
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RISK
open
Exploit-DBVexDay Proof
Orbit Downloader - Connecting Log Creation Buffer Overflow (Metasploit)
CVE-2009-0187remotewindows09 May 2010
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - isComponentInstalled Overflow (Metasploit)
CVE-2006-1016remotewindows09 May 2010
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Win
50RISK
open
Exploit-DBVexDay Proof
CA BrightStor ARCserve - Tape Engine Buffer Overflow (Metasploit)
CVE-2006-6076remotewindows09 May 2010
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open
Exploit-DBVexDay Proof
SAP AG SAPgui EAI WebViewer3D - Remote Buffer Overflow (Metasploit)
CVE-2007-4475remotewindows09 May 2010
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RISK
open
Exploit-DBVexDay Proof
Kazaa Altnet Download Manager - ActiveX Control Buffer Overflow (Metasploit)
CVE-2007-5217remotewindows09 May 2010
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) K
43RISK
open
Exploit-DBVexDay Proof
Amaya Browser 11.0 - bdo tag Overflow (Metasploit)
CVE-2009-0323remotewindows09 May 2010
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RISK
open
Exploit-DBVexDay Proof
Macrovision Installshield Update Service - Remote Buffer Overflow (Metasploit)
CVE-2007-5660remotewindows09 May 2010
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISK
open
Exploit-DBVexDay Proof
Juniper SSL-VPN IVE - 'JuniperSetupDLL.dll' ActiveX Control Buffer Overflow (Metasploit)
CVE-2006-2086remotewindows09 May 2010
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juni
50RISK
open
previouspage 376 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.