Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
CVE-2010-4930webappsphp21 Sep 2010
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control 'debug' Remote Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 Sep 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-0824doswindows21 Sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute
28RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 Sep 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Shell LNK Code Execution (MS10-046) (Metasploit)
CVE-2010-2568HIGHunder attackremotewindows21 Sep 2010
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISK
open
Exploit-DBVexDay Proof
wpQuiz 2.7 - Authentication Bypass
CVE-2010-3608webappsphp21 Sep 2010
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - SMB Relay Code Execution (MS08-068) (Metasploit)
CVE-2008-4037remotewindows21 Sep 2010
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RISK
open
Exploit-DBVexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
CVE-2010-2961locallinux21 Sep 2010
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISK
open
Exploit-DBVexDay Proof
Unreal Tournament 2004 (Windows) - 'secure' Remote Overflow (Metasploit)
CVE-2004-0608remotewindows20 Sep 2010
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open
Exploit-DBVexDay Proof
Chilkat Crypt - ActiveX WriteFile Unsafe Method (Metasploit)
CVE-2008-5002remotewindows20 Sep 2010
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISK
open
Exploit-DBVexDay Proof
BakBone NetVault - Remote Heap Overflow (Metasploit)
CVE-2005-1009remotewindows20 Sep 2010
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a mod
50RISK
open
Exploit-DBVexDay Proof
QBik WinGate WWW Proxy Server - URL Processing Overflow (Metasploit)
CVE-2006-2926remotewindows20 Sep 2010
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISK
open
Exploit-DBVexDay Proof
Apple iPhone MobileSafari LibTIFF - 'browser' Remote Buffer Overflow (Metasploit) (1)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
Racer 0.5.3 Beta 5 - Remote Buffer Overflow (Metasploit)
CVE-2007-4370remotewindows20 Sep 2010
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
Madwifi - SIOCGIWSCAN Buffer Overflow (Metasploit)
CVE-2006-6332remotelinux20 Sep 2010
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RISK
open
Exploit-DBVexDay Proof
WebSTAR FTP Server - USER Overflow (Metasploit)
CVE-2004-0695remoteosx20 Sep 2010
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISK
open
Exploit-DBVexDay Proof
TFTPD32 < 2.21 - 'Filename' Remote Buffer Overflow (Metasploit)
CVE-2002-2226remotewindows20 Sep 2010
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'createTextRange()' Code Execution (MS06-013) (Metasploit)
CVE-2006-1359remotewindows20 Sep 2010
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISK
open
Exploit-DBVexDay Proof
OpenX - 'banner-edit.php' Arbitrary File Upload / PHP Code Execution (Metasploit)
CVE-2009-4098remotephp20 Sep 2010
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate
43RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox - location.QueryInterface() Code Execution (Metasploit)
CVE-2006-0295remotemultiple20 Sep 2010
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COM CreateObject Code Execution (MS06-014/MS06-073) (Metasploit)
CVE-2006-0003remotewindows20 Sep 2010
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISK
open
Exploit-DBVexDay Proof
AppleFileServer (OSX) - LoginExt PathName Overflow (Metasploit)
CVE-2004-0430remoteosx20 Sep 2010
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitr
50RISK
open
Exploit-DBVexDay Proof
eIQNetworks ESA - Topology DELETEDEVICE Overflow (Metasploit)
CVE-2006-3838remotewindows20 Sep 2010
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open
Exploit-DBVexDay Proof
Mercantec SoftCart - CGI Overflow (Metasploit)
CVE-2004-2221remotewindows20 Sep 2010
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long
50RISK
open
Exploit-DBVexDay Proof
eIQNetworks ESA - License Manager LICMGR_ADDLICENSE Overflow (Metasploit)
CVE-2006-3838remotewindows20 Sep 2010
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.5 - 'escape()' Return Value Memory Corruption (Metasploit)
CVE-2009-2477remotemultiple20 Sep 2010
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISK
open
Exploit-DBVexDay Proof
HP - 'OmniInet.exe' MSG_PROTOCOL Buffer Overflow (Metasploit) (2)
CVE-2007-2280remotewindows20 Sep 2010
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager c
50RISK
open
Exploit-DBVexDay Proof
Mozilla Suite/Firefox - InstallVersion->compareTo() Code Execution (Metasploit)
CVE-2005-2265remotewindows20 Sep 2010
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open
Exploit-DBVexDay Proof
Unreal Tournament 2004 (Linux) - 'secure' Remote Overflow (Metasploit)
CVE-2004-0608remotelinux20 Sep 2010
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier,
60RISK
open
Exploit-DBVexDay Proof
Microsoft Help Center - Cross-Site Scripting / Command Execution (MS10-042) (Metasploit)
CVE-2010-1885remotewindows20 Sep 2010
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RISK
open
previouspage 178 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.