Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Article Directory - 'page.php' Blind SQL Injection
CVE-2009-2235webappsphp21 May 2009
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Article Directory - Authentication Bypass
CVE-2009-2236webappsphp21 May 2009
SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
Flash Quiz Beta 2 - Multiple SQL Injections
CVE-2009-1843webappsphp21 May 2009
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
asp inline Corporate Calendar - SQL Injection / Cross-Site Scripting
CVE-2009-2241webappsasp21 May 2009
Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
ChinaGames - 'CGAgent.dll' ActiveX Remote Code Execution
CVE-2009-1800remotewindows21 May 2009
Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames i
28RISK
open
Exploit-DBVexDay Proof
Kingsoft Webshield 1.1.0.62 - Cross-Site Scripting / Remote Command Execution
CVE-2009-1786webappsphp20 May 2009
The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a syml
23RISK
open
Exploit-DBVexDay Proof
Sun Java System Communications Express 6.3 - 'UWCMain' Cross-Site Scripting
CVE-2009-1729webappsjava20 May 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - Java applet Remote Deserialization Remote (2)
CVE-2008-5353remoteosx20 May 2009
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISK
open
Exploit-DBVexDay Proof
Sun Java System Communications Express 6.3 - 'search.xml' Cross-Site Scripting
CVE-2009-1729webappsjava20 May 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3
23RISK
open
Exploit-DBVexDay Proof
Profense 2.2.20/2.4.2 - Web Application Firewall Security Bypass
CVE-2009-1593webappsphp20 May 2009
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "neg
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Casino 0.3.1 - Multiple SQL Injections s
CVE-2009-2239webappsphp20 May 2009
SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3)
23RISK
open
Exploit-DBVexDay Proof
DMXReady Registration Manager 1.1 - Arbitrary File Upload
CVE-2009-2238webappsasp20 May 2009
Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXRea
23RISK
open
Exploit-DBVexDay Proof
Samba 3.3.5 - Format String / Security Bypass
CVE-2009-1886remotelinux19 May 2009
Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context
28RISK
open
Exploit-DBVexDay Proof
DirectAdmin 1.33.6 - 'CMD_REDIRECT' Cross-Site Scripting
CVE-2009-2216webappsjava19 May 2009
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to in
23RISK
open
Exploit-DBVexDay Proof
WebKit - 'parent/top' Cross Domain Scripting
CVE-2009-1724remotemultiple19 May 2009
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone
23RISK
open
Exploit-DBVexDay Proof
OpenSSL 0.9.8k/1.0.0-beta2 - DTLS Remote Memory Exhaustion Denial of Service
CVE-2009-1379dosmultiple18 May 2009
Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 a
28RISK
open
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (1)
CVE-2009-0961remotehardware17 May 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RISK
open
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (3)
CVE-2009-0961remotehardware17 May 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RISK
open
Exploit-DBVexDay Proof
Apple iPhone 2.2.1 - Call Approval Dialog Security Bypass (2)
CVE-2009-0961remotehardware17 May 2009
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the cal
23RISK
open
Exploit-DBVexDay Proof
Irssi 0.8.13 - 'WALLOPS' Message Off-by-One Heap Memory Corruption
CVE-2009-1959doslinux15 May 2009
Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to
23RISK
open
Exploit-DBVexDay Proof
Webmedia Explorer 5.0.9/5.10 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-2107webappsphp15 May 2009
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remot
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass (1)
CVE-2009-1676remotewindows15 May 2009
20RISK
open
Exploit-DBVexDay Proof
Lussumo Vanilla 1.1.5/1.1.7 - 'updatecheck.php' Cross-Site Scripting
CVE-2009-1845webappsphp15 May 2009
Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attack
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass (1)
CVE-2009-1535remotewindows15 May 2009
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RISK
open
Exploit-DBVexDay Proof
Ascad Networks 5 - Products Insecure Cookie Handling
CVE-2009-2003webappsphp14 May 2009
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x (Gentoo 2.6.29rc1) - 'ptrace_attach' Local Privilege Escalation
CVE-2009-1527locallinux13 May 2009
Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users
23RISK
open
Exploit-DBVexDay Proof
IPsec-Tools < 0.7.2 (racoon frag-isakmp) - Multiple Remote Denial of Service Vulnerabilities (PoC)
CVE-2009-1574dosmultiple13 May 2009
racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafte
28RISK
open
Exploit-DBVexDay Proof
CastRipper 2.50.70 - '.pls' Universal Stack Overflow
CVE-2009-5137localwindows12 May 2009
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a lo
23RISK
open
Exploit-DBVexDay Proof
Apple Safari 3.2.2 - 'feed:' URI Multiple Input Validation Vulnerabilities
CVE-2009-0162remotemultiple12 May 2009
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7
23RISK
open
Exploit-DBVexDay Proof
CastRipper 2.50.70 - '.m3u' Universal Stack Overflow
CVE-2009-1667localwindows12 May 2009
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a lo
28RISK
open
previouspage 447 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.