Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Solar FTP Server Malformed USER Denial of Service
CVE-2011-10029HIGH22 Feb 2011
Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
36RISK
open
Metasploit600
Sun Java Applet2ClassLoader Remote Code Execution
CVE-2010-445215 Feb 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RISK
open
Metasploit300
xRadio 0.95b Buffer Overflow
CVE-2008-278908 Feb 2011
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RISK
open
Metasploit600
HP Data Protector 6 EXEC_CMD Remote Code Execution
CVE-2011-092307 Feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RISK
open
Metasploit500
EMC Replication Manager Command Execution
CVE-2011-064707 Feb 2011
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x
50RISK
open
Metasploit300
HP Data Protector 6.1 EXEC_CMD Command Execution
CVE-2011-092307 Feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RISK
open
Metasploit300
VSFTPD 2.3.2 and Earlier STAT Denial of Service
CVE-2011-076203 Feb 2011
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RISK
open
Metasploit600
QuickShare File Server 1.2.1 Directory Traversal Vulnerability
CVE-2011-10010CRITICAL03 Feb 2011
QuickShare File Server 1.2.1 Path Traversal RCE
63RISK
open
Metasploit300
Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability
CVE-2011-007302 Feb 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RISK
open
Metasploit600
HP OpenView Performance Insight Server Backdoor Account Code Execution
CVE-2011-027631 Jan 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RISK
open
Metasploit400
VideoLAN VLC MKV Memory Corruption
CVE-2011-053131 Jan 2011
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RISK
open
Metasploit300
AOL Desktop 9.6 RTX Buffer Overflow
CVE-2011-10027HIGH31 Jan 2011
AOL Desktop 9.6 RTX Stack-Based Buffer Overflow
36RISK
open
Metasploit400
Real Networks Netzip Classic 7.5.1 86 File Parsing Buffer Overflow Vulnerability
CVE-2011-10016CRITICAL30 Jan 2011
Real Networks Netzip Classic 7.5.1.86 File Parsing Buffer Overflow
43RISK
open
Metasploit200
GoldenFTP PASS Stack Buffer Overflow
CVE-2006-657623 Jan 2011
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open
Metasploit600
Oracle Database Client System Analyzer Arbitrary File Upload
CVE-2010-360018 Jan 2011
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RISK
open
Metasploit500
Sielco Sistemi Winlog Buffer Overflow
CVE-2011-051713 Jan 2011
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISK
open
Metasploit300
HP OpenView NNM nnmRptConfig nameParams Buffer Overflow
CVE-2011-026610 Jan 2011
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RISK
open
Metasploit300
HP OpenView NNM nnmRptConfig.exe schdParams Buffer Overflow
CVE-2011-026710 Jan 2011
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RISK
open
Metasploit300
HP Data Protector Manager RDS DOS
CVE-2011-051408 Jan 2011
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash)
50RISK
open
Metasploit200
NetSupport Manager Agent Remote Buffer Overflow
CVE-2011-040408 Jan 2011
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RISK
open
Metasploit300
Synology Forget Password User Enumeration Scanner
CVE-2017-955405 Jan 2011
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RISK
open
Metasploit600
Axis2 / SAP BusinessObjects Authenticated Code Execution (via SOAP)
CVE-2010-021930 Dec 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
Metasploit400
Kolibri HTTP Server HEAD Buffer Overflow
CVE-2002-226826 Dec 2010
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RISK
open
Metasploit600
Citrix Access Gateway Command Execution
CVE-2010-456621 Dec 2010
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and
43RISK
open
Metasploit300
Microsoft IIS FTP Server Encoded Response Overflow Trigger
CVE-2010-397221 Dec 2010
Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0
60RISK
open
Metasploit500
Microsoft WMI Administration Tools ActiveX Buffer Overflow
CVE-2010-397321 Dec 2010
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RISK
open
Metasploit600
Redmine SCM Repository Arbitrary Command Execution
CVE-2011-492919 Dec 2010
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attacke
50RISK
open
Metasploit500
MS11-006 Microsoft Windows CreateSizedDIBSECTION Stack Buffer Overflow
CVE-2010-397015 Dec 2010
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RISK
open
Metasploit600
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
CVE-2010-396414 Dec 2010
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Serve
60RISK
open
Metasploit300
Crystal Reports CrystalPrintControl ActiveX ServerResourceVersion Property Overflow
CVE-2010-259014 Dec 2010
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.