Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit200
Firefox nsSVGValue Out-of-Bounds Access Vulnerability
CVE-2011-365806 Dec 2011
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAtt
50RISK
open
Metasploit200
Adobe Reader U3D Memory Corruption Vulnerability
CVE-2011-2462HIGHunder attack06 Dec 2011
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, a
100RISK
open
Metasploit300
SCADA 3S CoDeSys CmpWebServer Stack Buffer Overflow
CVE-2011-500702 Dec 2011
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB
60RISK
open
Metasploit600
QEMU Monitor HMP 'migrate' Command Execution
CVE-2019-1292802 Dec 2011
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote
23RISK
open
Metasploit400
CCMPlayer 1.5 m3u Playlist Stack Based Buffer Overflow
CVE-2011-517030 Nov 2011
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code vi
50RISK
open
Metasploit600
WikkaWiki 1.3.2 Spam Logging PHP Injection
CVE-2011-445130 Nov 2011
libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to w
43RISK
open
Metasploit200
MS11-080 AfdJoinLeaf Privilege Escalation
CVE-2011-2005HIGHunder attack30 Nov 2011
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RISK
open
Metasploit300
Avid Media Composer 5.5 - Avid Phonetic Indexer Buffer Overflow
CVE-2011-500329 Nov 2011
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier a
50RISK
open
Metasploit600
Family Connections less.php Remote Command Execution
CVE-2011-513029 Nov 2011
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RISK
open
Metasploit600
V-CMS PHP File Upload and Execute
CVE-2011-482827 Nov 2011
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote atta
50RISK
open
Metasploit300
Yaws Web Server Directory Traversal
CVE-2011-435025 Nov 2011
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user cou
23RISK
open
Metasploit600
Hastymail 2.1.1 RC1 Command Injection
CVE-2011-454222 Nov 2011
Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] paramet
43RISK
open
Metasploit300
VMware Update Manager 4 Directory Traversal
CVE-2011-440421 Nov 2011
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 bef
50RISK
open
Metasploit600
HP StorageWorks P4000 Virtual SAN Appliance Command Execution
CVE-2012-436111 Nov 2011
lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to exe
50RISK
open
Metasploit600
Support Incident Tracker Remote Command Execution
CVE-2011-382910 Nov 2011
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive in
43RISK
open
Metasploit600
Support Incident Tracker Remote Command Execution
CVE-2011-383310 Nov 2011
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RISK
open
Metasploit600
PmWiki pagelist.php Remote PHP Code Injection Exploit
CVE-2011-445309 Nov 2011
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitra
50RISK
open
Metasploit300
AbsoluteFTP 1.9.6 - 2.2.10 LIST Command Remote Buffer Overflow
CVE-2011-516409 Nov 2011
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute ar
43RISK
open
Metasploit400
Aviosoft Digital TV Player Professional 1.0 Stack Buffer Overflow
CVE-2011-449609 Nov 2011
Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka
23RISK
open
Metasploit600
InduSoft Web Studio Arbitrary Upload Remote Code Execution
CVE-2011-405104 Nov 2011
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RISK
open
Metasploit600
HP Data Protector 6.10/6.11/6.20 Install Service
CVE-2011-092202 Nov 2011
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RISK
open
Metasploit600
Novell ZENworks Asset Management Remote Execution
CVE-2011-265302 Nov 2011
Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote at
60RISK
open
Metasploit300
HP OpenView Network Node Manager ov.dll _OVBuildPath Buffer Overflow
CVE-2011-316701 Nov 2011
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute
50RISK
open
Metasploit300
NJStar Communicator 3.00 MiniSMTP Buffer Overflow
CVE-2011-404031 Oct 2011
Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a cra
50RISK
open
Metasploit600
phpLDAPadmin query_engine Remote PHP Code Injection
CVE-2011-407524 Oct 2011
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISK
open
Metasploit300
HP Power Manager 'formExportDataLogs' Buffer Overflow
CVE-2009-399919 Oct 2011
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISK
open
Metasploit300
AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution
CVE-2011-265719 Oct 2011
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in Laun
50RISK
open
Metasploit600
Java Applet Rhino Script Engine Remote Code Execution
CVE-2011-3544CRITICALunder attack18 Oct 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and
100RISK
open
Metasploit300
Java RMI Server Insecure Endpoint Code Execution Scanner
CVE-2011-355615 Oct 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISK
open
Metasploit600
Java RMI Server Insecure Default Configuration Java Code Execution
CVE-2011-355615 Oct 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.