Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit200
Novell NetWare LSASS CIFS.NLM Driver Stack Buffer Overflow
CVE-2005-285221 Jan 2007
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a den
50RISK
open
Metasploit200
CA BrightStor ARCserve Message Engine Buffer Overflow
CVE-2007-016911 Jan 2007
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10
50RISK
open
Metasploit200
Novell NetMail IMAP AUTHENTICATE Buffer Overflow
CVE-2005-175807 Jan 2007
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers
23RISK
open
Metasploit300
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
CVE-2007-001501 Jan 2007
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open
Metasploit200
Novell NetMail NMAP STOR Buffer Overflow
CVE-2006-642423 Dec 2006
Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by ap
50RISK
open
Metasploit200
Novell NetMail IMAP APPEND Buffer Overflow
CVE-2006-642523 Dec 2006
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISK
open
Metasploit200
Novell NetMail IMAP SUBSCRIBE Buffer Overflow
CVE-2006-676123 Dec 2006
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RISK
open
Metasploit500
AstonSoft DeepBurner (DBR File) Path Buffer Overflow
CVE-2006-666519 Dec 2006
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISK
open
Metasploit500
MailEnable IMAPD (2.34/2.35) Login Request Buffer Overflow
CVE-2006-642311 Dec 2006
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Pro
50RISK
open
Metasploit300
FileZilla FTP Server Malformed PORT Denial of Service
CVE-2006-656511 Dec 2006
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RISK
open
Metasploit500
3CTftpSvc TFTP Long Mode Buffer Overflow
CVE-2006-618327 Nov 2006
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISK
open
Metasploit200
Allied Telesyn TFTP Server 1.9 Long Filename Overflow
CVE-2006-618427 Nov 2006
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open
Metasploit500
ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)
CVE-2006-581526 Nov 2006
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably auth
60RISK
open
Metasploit200
CA BrightStor ARCserve Tape Engine Buffer Overflow
CVE-2006-607621 Nov 2006
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RISK
open
Metasploit400
XMPlay 3.3.0.4 (ASX Filename) Buffer Overflow
CVE-2006-606321 Nov 2006
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open
Metasploit400
MS06-066 Microsoft Services nwwks.dll Module Exploit
CVE-2006-468814 Nov 2006
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open
Metasploit0
MS06-070 Microsoft Workstation Service NetpManageIPCConnect Overflow
CVE-2006-469114 Nov 2006
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RISK
open
Metasploit400
MS06-066 Microsoft Services nwapi32.dll Module Exploit
CVE-2006-468814 Nov 2006
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RISK
open
Metasploit300
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
CVE-2006-477714 Nov 2006
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RISK
open
Metasploit600
America Online ICQ ActiveX Control Arbitrary File Download and Execute
CVE-2006-565006 Nov 2006
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute
50RISK
open
Metasploit200
Omni-NFS Server Buffer Overflow
CVE-2006-578006 Nov 2006
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RISK
open
Metasploit300
TikiWiki Information Disclosure
CVE-2006-570201 Nov 2006
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_m
50RISK
open
Metasploit300
Microsoft Windows NAT Helper Denial of Service
CVE-2006-561426 Oct 2006
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISK
open
Metasploit500
Novell eDirectory NDS Server Host Header Overflow
CVE-2006-547821 Oct 2006
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RISK
open
Metasploit600
Solaris libnspr NSPR_LOG_FILE Privilege Escalation
CVE-2006-484211 Oct 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISK
open
Metasploit300
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
CVE-2006-574510 Oct 2006
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML
60RISK
open
Metasploit200
SHTTPD URI-Encoded POST Request Overflow
CVE-2006-521606 Oct 2006
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RISK
open
Metasploit200
CA BrightStor ARCserve Message Engine Heap Overflow
CVE-2006-514305 Oct 2006
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RISK
open
Metasploit500
NaviCOPA 2.0.1 URL Handling Buffer Overflow
CVE-2006-511228 Sep 2006
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open
Metasploit500
TFTPDWIN v0.4.2 Long Filename Buffer Overflow
CVE-2006-494821 Sep 2006
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.