Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Adobe Reader 8.1.4/9.1 - 'GetAnnots()' Remote Code Execution
CVE-2009-1492remotelinux
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RISK
open
ReferênciaVexDay Proof
Adobe 8.1.4/9.1 - 'customDictionaryOpen()' Code Execution
CVE-2009-1493remotelinux
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and
28RISK
open
ReferênciaVexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
CVE-2009-1511doswindows
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RISK
open
ReferênciaVexDay Proof
Google Chrome 1.0.154.53 - Null Pointer Remote Crash
CVE-2009-1514doswindows
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application
23RISK
open
ReferênciaVexDay Proof
Icewarp Merak Mail Server 9.4.1 - 'Base64FileEncode()' Buffer Overflow (PoC)
CVE-2009-1516doswindows
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1
23RISK
open
ReferênciaVexDay Proof
Norton Ghost Support module for EasySetup wizard - Remote Denial of Service (PoC)
CVE-2009-1517doswindows
Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in
23RISK
open
ReferênciaVexDay Proof
pecio CMS 1.1.5 - 'index.php?language' Local File Inclusion
CVE-2009-1519webappsphp
Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
AGTC MyShop 3.2 - Insecure Cookie Handling
CVE-2009-1549webappsphp
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accep
23RISK
open
ReferênciaVexDay Proof
Qt QuickTeam - Multiple Remote File Inclusions
CVE-2009-1551webappsphp
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP cod
28RISK
open
ReferênciaVexDay Proof
TemaTres 1.0.3 - Blind SQL Injection
CVE-2009-1584webappsphp
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5875webappsphp
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
ReferênciaVexDay Proof
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
CVE-2008-5877webappsphp
Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc
23RISK
open
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Remote Buffer Overflow
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Universal Overwrite (SEH)
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
Leap CMS 0.1.4 - 'searchterm' Blind SQL Injection
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RISK
open
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1613webappsphp
Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at
23RISK
open
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1614webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr
23RISK
open
ReferênciaVexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
CVE-2009-1615webappsphp
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading
23RISK
open
ReferênciaVexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
CVE-2009-1619webappsphp
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RISK
open
ReferênciaVexDay Proof
Opencart 1.1.8 - 'route' Local File Inclusion
CVE-2009-1621webappsphp
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1624webappsphp
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi
23RISK
open
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
CVE-2009-1627doswindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
CVE-2009-1627localwindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.asx' 'HREF' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RISK
open
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.RAM' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RISK
open
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.asx HREF' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Active NewsLetter 4.3 - Authentication Bypass
CVE-2008-6286webappsasp
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
cTorrent/DTorrent - '.torrent' Local Buffer Overflow
CVE-2009-1759locallinux
Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent)
28RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.6.2 - 'langpref' Local File Inclusion
CVE-2009-1765webappsphp
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.