Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
BisonWare BisonFTP Server Buffer Overflow
CVE-1999-151007 Aug 2011
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RISK
open
Metasploit600
Sun/Oracle GlassFish Server Authenticated Code Execution
CVE-2011-080704 Aug 2011
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISK
open
Metasploit600
CA Arcserve D2D GWT RPC Credential Information Disclosure
CVE-2011-301125 Jul 2011
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RISK
open
Metasploit600
Apple Safari Webkit libxslt Arbitrary File Creation
CVE-2011-177420 Jul 2011
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISK
open
Metasploit600
Wireshark console.lua Pre-Loading Script Execution
CVE-2011-336018 Jul 2011
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RISK
open
Metasploit300
Citrix Gateway ActiveX Control Stack Based Buffer Overflow Vulnerability
CVE-2011-288214 Jul 2011
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RISK
open
Metasploit600
LifeSize Room Command Injection
CVE-2011-276313 Jul 2011
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RISK
open
Metasploit600
WeBid converter.php Remote PHP Code Injection
CVE-2011-10011CRITICAL05 Jul 2011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISK
open
Metasploit600
VSFTPD 2.3.4 Backdoor Command Execution
CVE-2011-252303 Jul 2011
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
Metasploit300
Kaillera 0.86 Server Denial of Service
CVE-2011-10020HIGH02 Jul 2011
Kaillera 0.86 Server DoS via Malformed UDP Packet
36RISK
open
Metasploit400
HP OmniInet.exe Opcode 20 Buffer Overflow
CVE-2011-186529 Jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open
Metasploit500
HP OmniInet.exe Opcode 27 Buffer Overflow
CVE-2011-186529 Jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISK
open
Metasploit300
Mozilla Firefox Array.reduceRight() Integer Overflow
CVE-2011-237121 Jun 2011
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RISK
open
Metasploit300
MS11-050 IE mshtml!CObjectElement Use After Free
CVE-2011-126016 Jun 2011
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RISK
open
Metasploit600
Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute
CVE-2011-203901 Jun 2011
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Win
50RISK
open
Metasploit400
IBM Tivoli Endpoint Manager POST Query Buffer Overflow
CVE-2011-122031 May 2011
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3
50RISK
open
Metasploit300
Sybase Easerver 6.3 Directory Traversal
CVE-2011-247425 May 2011
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers
30RISK
open
Metasploit300
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 May 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISK
open
Metasploit400
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 May 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISK
open
Metasploit500
VisiWave VWR File Parsing Vulnerability
CVE-2011-238620 May 2011
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to
50RISK
open
Metasploit300
MPlayer SAMI Subtitle File Buffer Overflow
CVE-2011-362519 May 2011
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RISK
open
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free Vulnerability
CVE-2011-006510 May 2011
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RISK
open
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free
CVE-2011-006510 May 2011
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RISK
open
Metasploit400
ICONICS WebHMI ActiveX Buffer Overflow
CVE-2011-208905 May 2011
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0
50RISK
open
Metasploit300
SPlayer 3.7 Content-Type Buffer Overflow
CVE-2011-10022HIGH04 May 2011
SPlayer 3.7 Content-Type Header Buffer Overflow
36RISK
open
Metasploit300
Tom Sawyer Software GET Extension Factory Remote Code Execution
CVE-2011-221703 May 2011
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RISK
open
Metasploit400
MJM QuickPlayer 1.00 Beta 60a / QuickPlayer 2010 .s3m Stack Buffer Overflow
CVE-2011-10023HIGH30 Apr 2011
MJM QuickPlayer <= 2010 .s3m Stack-Based Buffer Overflow
36RISK
open
Metasploit400
MJM Core Player 2011 .s3m Stack Buffer Overflow
CVE-2011-10024HIGH30 Apr 2011
MJM Core Player 2011 .s3m File Stack-Based Buffer Overflow
36RISK
open
Metasploit300
NetOp Remote Control Client 9.5 Buffer Overflow
CVE-2011-10012HIGH28 Apr 2011
NetOp Remote Control Client 9.5 .dws File Buffer Overflow
36RISK
open
Metasploit400
Magix Musik Maker 16 .mmm Stack Buffer Overflow
CVE-2011-10021HIGH26 Apr 2011
Magix Musik Maker <= v16 .mmm Stack-Based Buffer Overflow
36RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.