Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
CVE-2008-398213 Oct 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
23RISK
open
Metasploit300
Oracle DB SQL Injection via SYS.LT.REMOVEWORKSPACE
CVE-2008-398413 Oct 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open
Metasploit300
Guild FTPd 0.999.8.11/0.999.14 Heap Corruption
CVE-2008-457212 Oct 2008
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Metasploit200
Computer Associates ARCserve REPORTREMOTEEXECUTECML Buffer Overflow
CVE-2008-439709 Oct 2008
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve
60RISK
open
Metasploit300
iseemedia / Roxio / MGI Software LPViewer ActiveX Control Buffer Overflow
CVE-2008-438406 Oct 2008
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISK
open
Metasploit300
mIRC PRIVMSG Handling Stack Buffer Overflow
CVE-2008-444902 Oct 2008
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISK
open
Metasploit600
phpScheduleIt PHP reserve.php start_date Parameter Arbitrary Code Injection
CVE-2008-613201 Oct 2008
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RISK
open
Metasploit300
WinFTP 2.3.0 NLST Denial of Service
CVE-2008-566626 Sep 2008
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISK
open
Metasploit500
DATAC RealWin SCADA Server Buffer Overflow
CVE-2008-432226 Sep 2008
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att
50RISK
open
Metasploit500
BEA Weblogic Transfer-Encoding Buffer Overflow
CVE-2008-400809 Sep 2008
Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 M
50RISK
open
Metasploit300
Windows Media Encoder 9 wmex.dll ActiveX Buffer Overflow
CVE-2008-300809 Sep 2008
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RISK
open
Metasploit400
Ultra Shareware Office Control ActiveX HttpUpload Buffer Overflow
CVE-2008-387827 Aug 2008
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RISK
open
Metasploit600
AWStats Totals multisort Remote Command Execution
CVE-2008-392226 Aug 2008
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences
50RISK
open
Metasploit100
activePDF WebGrabber ActiveX Control Buffer Overflow
CVE-2008-20001HIGH26 Aug 2008
activePDF WebGrabber ActiveX Control Buffer Overflow
36RISK
open
Metasploit300
SoftArtisans XFile FileManager ActiveX Control Buffer Overflow
CVE-2007-168225 Aug 2008
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.
43RISK
open
Metasploit300
Microsoft Visual Studio Mdmask32.ocx ActiveX Stack Buffer Overflow
CVE-2008-370413 Aug 2008
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISK
open
Metasploit500
Racer v0.5.3 Beta 5 Buffer Overflow
CVE-2007-437010 Aug 2008
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISK
open
Metasploit300
Ruby WEBrick::HTTP::DefaultFileHandler DoS
CVE-2008-365608 Aug 2008
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFile
60RISK
open
Metasploit400
WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow
CVE-2008-355806 Aug 2008
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before
50RISK
open
Metasploit300
DNS BailiWicked Host Attack
CVE-2008-144721 Jul 2008
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISK
open
Metasploit300
DNS BailiWicked Domain Attack
CVE-2008-144721 Jul 2008
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISK
open
Metasploit500
Oracle Weblogic Apache Connector POST Request Buffer Overflow
CVE-2008-325717 Jul 2008
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RISK
open
Metasploit0
Trixbox langChoice PHP Local File Inclusion
CVE-2008-682509 Jul 2008
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to
43RISK
open
Metasploit600
Snapshot Viewer for Microsoft Access ActiveX Control Arbitrary File Download
CVE-2008-246307 Jul 2008
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snaps
50RISK
open
Metasploit200
OpenTFTP SP 1.4 Error Packet Overflow
CVE-2008-216105 Jul 2008
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execut
50RISK
open
Metasploit300
Novell GroupWise Messenger Client Buffer Overflow
CVE-2008-270302 Jul 2008
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow rem
50RISK
open
Metasploit200
Novell Client 4.91 SP4 nwfs.sys Local Privilege Escalation
CVE-2008-315826 Jun 2008
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possi
38RISK
open
Metasploit300
Novell iPrint Client ActiveX Control Buffer Overflow
CVE-2008-290816 Jun 2008
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows bef
50RISK
open
Metasploit300
VeryPDF PDFView OCX ActiveX OpenPDF Heap Overflow
CVE-2008-549216 Jun 2008
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISK
open
Metasploit600
BASE base_qry_common Remote File Include
CVE-2006-268514 Jun 2008
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_gl
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.