Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
ReferênciaVexDay Proof
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
CVE-2009-0833doswindows
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2009-1315webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri
23RISK
open
Referência
CVE-2009-3271
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel:
23RISK
open
Referência
CVE-2018-0833
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RISK
open
Referência
CVE-2016-0121
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Referência
CVE-2011-1524
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) bef
23RISK
open
Referência
CVE-2021-29995
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Barryvan Compo Manager 0.3 - Remote File Inclusion
CVE-2008-1126webappsphp
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arb
28RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFENC.sys' Local Kernel Ring0 link list zero (PoC)
CVE-2008-1138doswindows
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a
23RISK
open
ReferênciaVexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
CVE-2008-1160remotehardware
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RISK
open
ReferênciaVexDay Proof
BM Classifieds 20080409 - Multiple SQL Injections
CVE-2008-1272webappsphp
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Adobe Acrobat Reader 8.1.2 - '.PDF' Remote Denial of Service (PoC)
CVE-2008-2549doswindows
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (applicat
35RISK
open
Referência
Webmin 1.900 - Remote Command Execution (Metasploit)
CVE-2019-9624remotecgi
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RISK
open
Referência
CVE-2017-10309
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow (PoC)
CVE-2007-0976doswindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open
Referência
CVE-2013-1606
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RISK
open
ReferênciaVexDay Proof
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
CVE-2007-1837webappsphp
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Referência
CVE-2010-4051
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
ReferênciaVexDay Proof
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
CVE-2007-2946doswindows
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RISK
open
Referência
CVE-2012-5329
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RISK
open
Referência
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISK
open
ReferênciaVexDay Proof
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
CVE-2006-5220webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
23RISK
open
ReferênciaVexDay Proof
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
CVE-2007-3487remotewindows
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
CVE-2008-1295webappsphp
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RISK
open
ReferênciaVexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
CVE-2008-6929webappsphp
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RISK
open
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
CVE-2009-1828dosmultiple
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RISK
open
Referência
CVE-2014-0372
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
previouspage 439 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.