Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
CVE-2009-3953HIGHunder attack13 Oct 2009
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISK
open
Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
CVE-2009-299013 Oct 2009
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RISK
open
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHunder attack08 Oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open
Metasploit500
HTTPDX h_handlepeer() Function Buffer Overflow
CVE-2009-371108 Oct 2009
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RISK
open
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHunder attack08 Oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISK
open
Metasploit500
AIX Calendar Manager Service Daemon (rpc.cmsd) Opcode 21 Buffer Overflow
CVE-2009-369907 Oct 2009
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through
50RISK
open
Metasploit300
Dopewars Denial of Service
CVE-2009-359105 Oct 2009
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RISK
open
Metasploit300
NTP.org ntpd Reserved Mode Denial of Service
CVE-2009-356304 Oct 2009
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba
30RISK
open
Metasploit300
Xlink FTP Client Buffer Overflow
CVE-2006-579203 Oct 2009
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RISK
open
Metasploit400
Xlink FTP Server Buffer Overflow
CVE-2006-579203 Oct 2009
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RISK
open
Metasploit500
InterSystems Cache UtilConfigHome.csp Argument Buffer Overflow
CVE-2009-20005CRITICAL29 Sep 2009
InterSystems Caché UtilConfigHome.csp Stack Buffer Overflow
63RISK
open
Metasploit600
Persits XUpload ActiveX MakeHttpRequest Directory Traversal
CVE-2009-369329 Sep 2009
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows rem
50RISK
open
Metasploit200
EMC ApplicationXtender (KeyWorks) ActiveX Control Buffer Overflow
CVE-2012-251529 Sep 2009
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHel
23RISK
open
Metasploit600
WinRAR Filename Spoofing
CVE-2014-125119HIGH28 Sep 2009
WinRAR < 5.00 Filename Spoofing RCE
36RISK
open
Metasploit600
Adobe RoboHelp Server 8 Arbitrary File Upload and Execute
CVE-2009-306823 Sep 2009
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows
60RISK
open
Metasploit500
Vermillion FTP Daemon PORT Command Memory Corruption
CVE-2010-20115CRITICAL23 Sep 2009
Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption
43RISK
open
Metasploit600
Zabbix Server Arbitrary Command Execution
CVE-2009-449810 Sep 2009
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via
50RISK
open
Metasploit600
Zabbix Agent net.tcp.listen Command Injection
CVE-2009-450210 Sep 2009
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote att
43RISK
open
Metasploit600
Symantec Altiris Deployment Solution ActiveX Control Arbitrary File Download and Execute
CVE-2009-302809 Sep 2009
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution
50RISK
open
Metasploit400
MS09-050 Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference
CVE-2009-310307 Sep 2009
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
Metasploit300
Microsoft IIS FTP Server LIST Stack Exhaustion
CVE-2009-252103 Sep 2009
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RISK
open
Metasploit500
MS09-053 Microsoft IIS FTP Server NLST Response Overflow
CVE-2009-302331 Aug 2009
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISK
open
Metasploit600
osCommerce 2.2 Arbitrary PHP Code Execution
CVE-2009-20006CRITICAL31 Aug 2009
osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution
63RISK
open
Metasploit300
Oracle Document Capture 10g ActiveX Control Buffer Overflow
CVE-2007-460728 Aug 2009
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open
Metasploit300
ProFTP 2.9 Banner Remote Buffer Overflow
CVE-2009-397625 Aug 2009
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu
43RISK
open
Metasploit500
ProShow Gold v4.0.2549 (PSH File) Stack Buffer Overflow
CVE-2009-321420 Aug 2009
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISK
open
Metasploit500
Xenorate 2.50 (.xpl) Universal Local Buffer Overflow (SEH)
CVE-2009-20003HIGH19 Aug 2009
Xenorate <= 2.50 .xpl File Stack-Based Buffer Overflow
36RISK
open
Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
CVE-2009-197818 Aug 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
50RISK
open
Metasploit400
VUPlayer CUE Buffer Overflow
CVE-2009-018218 Aug 2009
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
Metasploit400
VUPlayer M3U Buffer Overflow
CVE-2006-625118 Aug 2009
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.