Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Mozilla Suite/Firefox - InstallVersion->compareTo() Code Execution (Metasploit)
CVE-2005-2265remotewindows20 Sep 2010
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of serv
50RISK
open
Exploit-DBVexDay Proof
iPhone MobileMail - LibTIFF Buffer Overflow (Metasploit)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Software Update - Command Execution (Metasploit)
CVE-2007-5863remoteosx20 Sep 2010
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (
43RISK
open
Exploit-DBVexDay Proof
Microsoft WINS - Service Memory Overwrite (MS04-045) (Metasploit)
CVE-2004-1080remotewindows20 Sep 2010
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remo
60RISK
open
Exploit-DBVexDay Proof
Mercur MailServer 5.0 - IMAP SP3 SELECT Buffer Overflow (Metasploit)
CVE-2006-1255remotewindows20 Sep 2010
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open
Exploit-DBVexDay Proof
Apple iPhone MobileSafari LibTIFF - 'email' Remote Buffer Overflow (Metasploit) (2)
CVE-2006-3459remotehardware20 Sep 2010
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Exploit-DBVexDay Proof
Sun Java JRE - getSoundbank 'file://' URI Buffer Overflow (Metasploit)
CVE-2009-3867remotemultiple20 Sep 2010
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, J
60RISK
open
Exploit-DBVexDay Proof
PHP 4 - Unserialize() ZVAL Reference Counter Overflow (Cookie) (Metasploit)
CVE-2007-1286remotemultiple20 Sep 2010
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.5 - 'escape()' Return Value Memory Corruption (Metasploit)
CVE-2009-2477remotemultiple20 Sep 2010
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISK
open
Exploit-DBVexDay Proof
Sun Java - Calendar Deserialization (Metasploit)
CVE-2008-5353remotemultiple20 Sep 2010
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISK
open
Exploit-DBVexDay Proof
PeerCast 0.1216 (Linux) - URL Handling Buffer Overflow (Metasploit)
CVE-2006-1148remotelinux20 Sep 2010
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISK
open
Exploit-DBVexDay Proof
PeerCast 0.1216 (Windows x86) - URL Handling Buffer Overflow (Metasploit)
CVE-2006-1148remotewindows_x8620 Sep 2010
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISK
open
Exploit-DBVexDay Proof
Microsoft Help Center - Cross-Site Scripting / Command Execution (MS10-042) (Metasploit)
CVE-2010-1885remotewindows20 Sep 2010
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RISK
open
Exploit-DBVexDay Proof
Apple Safari - Archive Metadata Command Execution (Metasploit)
CVE-2006-0848remoteunix20 Sep 2010
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex
50RISK
open
Exploit-DBVexDay Proof
Novell iPrint Client Browser Plugin - 'call-back-url' Remote Stack Overflow
CVE-2010-1527remotewindows19 Sep 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
SmarterMail 7.1.3876 - Directory Traversal
CVE-2010-3486remotewindows19 Sep 2010
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISK
open
Exploit-DBVexDay Proof
BoutikOne 1.0 - SQL Injection
CVE-2010-3479webappsphp19 Sep 2010
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4927webappsphp18 Sep 2010
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Apple QuickTime FLI LinePacket - Remote Code Execution
CVE-2010-0520doswindows18 Sep 2010
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attacker
28RISK
open
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4928webappsphp18 Sep 2010
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISK
open
Exploit-DBVexDay Proof
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
CVE-2010-4954webappsphp18 Sep 2010
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.6.4 - 'Plugin' EnsureCachedAttrParamArrays Remote Code Execution
CVE-2010-1214doswindows17 Sep 2010
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remot
23RISK
open
Exploit-DBVexDay Proof
Netautor Professional 5.5 - 'login2.php' Cross-Site Scripting
CVE-2010-3489webappsphp17 Sep 2010
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor P
23RISK
open
Exploit-DBVexDay Proof
BACnet OPC Client - Local Buffer Overflow (1)
CVE-2010-4740localwindows16 Sep 2010
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation
CVE-2010-3081locallinux_x86-6416 Sep 2010
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc4-git2 (x86-64) - 'ia32syscall' Emulation Privilege Escalation
CVE-2010-3301locallinux_x86-6416 Sep 2010
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on
23RISK
open
Exploit-DBVexDay Proof
mojoportal - Multiple Vulnerabilities
CVE-2010-3602webappsasp16 Sep 2010
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
mojoportal - Multiple Vulnerabilities
CVE-2010-3603webappsasp16 Sep 2010
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
CVE-2010-1248doswindows16 Sep 2010
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISK
open
Exploit-DBVexDay Proof
Axigen Webmail 1.0.1 - Directory Traversal
CVE-2010-3460remotewindows15 Sep 2010
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers
23RISK
open
previouspage 351 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.