Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,814cataloged exploits
32,125CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit600
Java RMIConnectionImpl Deserialization Privilege Escalation
CVE-2010-009431 Mar 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RISK
open
Metasploit600
Java Statement.invoke() Trusted Method Chain Privilege Escalation
CVE-2010-0840CRITICALunder attack31 Mar 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RISK
open
Metasploit500
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
CVE-2010-084230 Mar 2010
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4
60RISK
open
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x21 Buffer Overflow
CVE-2012-221530 Mar 2010
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RISK
open
Metasploit600
Novell ZENworks Configuration Management Remote Execution
CVE-2010-532430 Mar 2010
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
60RISK
open
Metasploit600
Adobe PDF Embedded EXE Social Engineering
CVE-2010-124029 Mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
Metasploit600
Adobe PDF Escape EXE Social Engineering (No JavaScript)
CVE-2010-124029 Mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
CVE-2009-164129 Mar 2010
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RISK
open
Metasploit400
Steinberg MyMP3Player 3.0 Buffer Overflow
CVE-2010-20123HIGH18 Mar 2010
Steinberg MyMP3Player <= 3.0.0.67 Buffer Overflow
36RISK
open
Metasploit500
VariCAD 2010-2.05 EN (DWB File) Stack Buffer Overflow
CVE-2010-20114HIGH17 Mar 2010
VariCAD EN <= 2010-2.05 .dwb File Stack Buffer Overflow
36RISK
open
Metasploit400
MS10-018 Microsoft Internet Explorer DHTML Behaviors Use After Free
CVE-2010-0806HIGHunder attack09 Mar 2010
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RISK
open
Metasploit400
MS10-018 Microsoft Internet Explorer Tabular Data Control ActiveX Memory Corruption
CVE-2010-080509 Mar 2010
The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and
60RISK
open
Metasploit600
Energizer DUO USB Battery Charger Arucer.dll Trojan Code Execution
CVE-2010-010305 Mar 2010
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISK
open
Metasploit300
Apache mod_isapi Dangling Pointer
CVE-2010-042505 Mar 2010
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RISK
open
Metasploit300
Viscom Image Viewer CP Pro 8.0/Gold 6.0 ActiveX Control
CVE-2010-519303 Mar 2010
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISK
open
Metasploit500
Orbital Viewer ORB File Parsing Buffer Overflow
CVE-2010-068827 Feb 2010
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a
50RISK
open
Metasploit500
MS10-022 Microsoft Internet Explorer Winhlp32.exe MsgBox Code Execution
CVE-2010-048326 Feb 2010
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RISK
open
Metasploit500
EasyFTP Server list.html path Stack Buffer Overflow
CVE-2010-20113CRITICAL18 Feb 2010
EasyFTP Server list.html path Stack Buffer Overflow
63RISK
open
Metasploit500
EasyFTP Server CWD Command Stack Buffer Overflow
CVE-2010-20121CRITICAL16 Feb 2010
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
Metasploit400
Adobe Acrobat Bundled LibTIFF Integer Overflow
CVE-2010-0188HIGHunder attackransomware16 Feb 2010
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RISK
open
Metasploit400
Hyleos ChemView ActiveX Control Stack Buffer Overflow
CVE-2010-067910 Feb 2010
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos Ch
50RISK
open
Metasploit400
MS10-004 Microsoft PowerPoint Viewer TextBytesAtom Stack Buffer Overflow
CVE-2010-003309 Feb 2010
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISK
open
Metasploit300
Oracle DB 10gR2, 11gR1/R2 DBMS_JVM_EXP_PERMS OS Command Execution
CVE-2010-086601 Feb 2010
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RISK
open
Metasploit300
Oracle DB 11g R1/R2 DBMS_JVM_EXP_PERMS OS Code Execution
CVE-2010-086601 Feb 2010
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RISK
open
Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow (loop)
CVE-2010-030427 Jan 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open
Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow
CVE-2010-030427 Jan 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open
Metasploit400
MySQL yaSSL CertDecoder::GetName Buffer Overflow
CVE-2009-448425 Jan 2010
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.
50RISK
open
Metasploit500
S.O.M.P.L 1.0 Player Buffer Overflow
CVE-2012-10053CRITICAL22 Jan 2010
Simple Web Server Connection Header Buffer Overflow
63RISK
open
Metasploit300
MS10-002 Microsoft Internet Explorer Object Memory Use-After-Free
CVE-2010-0248HIGH21 Jan 2010
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers
68RISK
open
Metasploit200
AOL 9.5 Phobos.Playlist Import() Stack-based Buffer Overflow
CVE-2010-10015HIGH20 Jan 2010
AOL <= 9.5 Phobos.Playlist 'Import()' Stack-Based Buffer Overflow
36RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.