Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit600
Mambo Cache_Lite Class mosConfig_absolute_path Remote File Include
CVE-2008-290514 Jun 2008
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RISK
open
Metasploit300
CitectSCADA/CitectFacilities ODBC Buffer Overflow
CVE-2008-263911 Jun 2008
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RISK
open
Metasploit600
Black Ice Cover Page ActiveX Control Arbitrary File Download
CVE-2008-268305 Jun 2008
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open
Metasploit200
DoubleTake/HP StorageWorks Storage Mirroring Service Authentication Overflow
CVE-2008-166104 Jun 2008
Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote a
50RISK
open
Metasploit600
Icona SpA C6 Messenger DownloaderActiveX Control Arbitrary File Download and Execute
CVE-2008-255103 Jun 2008
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force
50RISK
open
Metasploit200
Alt-N SecurityGateway username Buffer Overflow
CVE-2008-419302 Jun 2008
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t
60RISK
open
Metasploit300
Creative Software AutoUpdate Engine ActiveX Control Buffer Overflow
CVE-2008-095528 May 2008
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISK
open
Metasploit300
EMC AlphaStor Device Manager Arbitrary Command Execution
CVE-2008-215727 May 2008
robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands
30RISK
open
Metasploit300
EMC AlphaStor Library Manager Arbitrary Command Execution
CVE-2008-215727 May 2008
robotd in the Library Manager in EMC AlphaStor 3.1 SP1 for Windows allows remote attackers to execute arbitrary commands
30RISK
open
Metasploit500
EMC AlphaStor Agent Buffer Overflow
CVE-2008-215827 May 2008
Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1
50RISK
open
Metasploit200
IBM Lotus Domino Sametime STMux.exe Stack Buffer Overflow
CVE-2008-249921 May 2008
Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1
60RISK
open
Metasploit200
IBM Lotus Domino Web Server Accept-Language Stack Buffer Overflow
CVE-2008-224020 May 2008
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows
50RISK
open
Metasploit300
Symantec Altiris DS SQL Injection
CVE-2008-228615 May 2008
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allow
50RISK
open
Metasploit600
Timbuktu Pro Directory Traversal/File Upload
CVE-2008-111710 May 2008
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISK
open
Metasploit300
OpenOffice OLE Importer DocumentSummaryInformation Stream Handling Overflow
CVE-2008-032017 Apr 2008
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of
50RISK
open
Metasploit500
BigAnt Server 2.50 SP1 Buffer Overflow
CVE-2008-191415 Apr 2008
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RISK
open
Metasploit200
BigAnt Server 2.2 Buffer Overflow
CVE-2008-191415 Apr 2008
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RISK
open
Metasploit500
Tumbleweed FileTransfer vcst_eu.dll ActiveX Control Buffer Overflow
CVE-2008-172407 Apr 2008
Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX cont
50RISK
open
Metasploit200
Computer Associates Alert Notification Buffer Overflow
CVE-2007-462004 Apr 2008
Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.
50RISK
open
Metasploit300
Orbit Downloader URL Unicode Conversion Overflow
CVE-2008-160203 Apr 2008
Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a
50RISK
open
Metasploit200
Borland CaliberRM StarTeam Multicast Service Buffer Overflow
CVE-2008-031102 Apr 2008
Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (ST
50RISK
open
Metasploit400
HP OpenView NNM 7.53, 7.51 OVAS.EXE Pre-Authentication Stack Buffer Overflow
CVE-2008-169702 Apr 2008
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RISK
open
Metasploit300
Wireshark LDAP Dissector DOS
CVE-2008-156228 Mar 2008
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of s
50RISK
open
Metasploit400
Quick FTP Pro 2.1 Transfer-Mode Overflow
CVE-2008-161027 Mar 2008
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RISK
open
Metasploit300
TFTP Server for Windows 1.4 ST WRQ Buffer Overflow
CVE-2008-161126 Mar 2008
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RISK
open
Metasploit200
Asus Dpcproxy Buffer Overflow
CVE-2008-149121 Mar 2008
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RISK
open
Metasploit300
CA BrightStor ARCserve Backup AddColumn() ActiveX Buffer Overflow
CVE-2008-147216 Mar 2008
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISK
open
Metasploit500
MDaemon 9.6.4 IMAPD FETCH Buffer Overflow
CVE-2008-135813 Mar 2008
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RISK
open
Metasploit300
RealPlayer rmoc3260.dll ActiveX Control Heap Corruption
CVE-2008-130908 Mar 2008
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RISK
open
Metasploit300
Symantec BackupExec Calendar Control Buffer Overflow
CVE-2007-601628 Feb 2008
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the schedul
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.