Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Evernew Free Joke Script - 'viewjokes.php' SQL Injection
CVE-2010-0630webappsphp01 Feb 2010
SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrar
23RISK
open
Exploit-DB
Home Of AlegroCart 1.1 - Cross-Site Request Forgery (Change Administrator Password)
CVE-2010-1611webappsphp01 Feb 2010
Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication o
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component AutartiTarot - Directory Traversal
CVE-2010-0801webappsphp01 Feb 2010
Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authe
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service
CVE-2010-0307doslinux_x86-6401 Feb 2010
The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensu
23RISK
open
Exploit-DBVexDay Proof
phpunity.newsmanager - Local File Inclusion
CVE-2010-0799webappsphp30 Jan 2010
Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component JE Event Calendar - SQL Injection
CVE-2010-0795webappsphp30 Jan 2010
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_dms 2.5.1 - SQL Injection
CVE-2010-0800webappsphp30 Jan 2010
SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allo
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component com_simplefaq - 'catid' Blind SQL Injection
CVE-2010-0632webappsphp30 Jan 2010
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open
Exploit-DB
IPB (nv2) Awards < 1.1.0 - SQL Injection
CVE-2010-0802webappsphp30 Jan 2010
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RISK
open
Exploit-DBVexDay Proof
COMTREND CT-507 IT ADSL Router - 'scvrtsrv.cmd' Cross-Site Scripting
CVE-2010-0470remotehardware29 Jan 2010
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
Hybserv2 - ':help' Denial of Service
CVE-2010-0303doslinux29 Jan 2010
mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a d
23RISK
open
Exploit-DBVexDay Proof
Wireshark 1.2.5 - 'LWRES getaddrbyname' Stack Buffer Overflow (PoC)
CVE-2010-0304dosmultiple29 Jan 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open
Exploit-DBVexDay Proof
Joomla! Component JE Quiz - 'eid' Blind SQL Injection
CVE-2010-0796webappsphp29 Jan 2010
SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
CommonSpot Server - '/utilities/longproc.cfm' Cross-Site Scripting
CVE-2010-0468webappscfm28 Jan 2010
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component CCNewsLetter - Local File Inclusion
CVE-2010-0467webappsphp28 Jan 2010
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RISK
open
Exploit-DBVexDay Proof
Audiotran 1.4.1 - '.pls' Local Stack Buffer Overflow (Metasploit)
CVE-2009-0476localwindows28 Jan 2010
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open
Exploit-DBVexDay Proof
Joomla! Component CCNewsLetter - Directory Traversal
CVE-2010-0467webappsphp28 Jan 2010
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RISK
open
Exploit-DB
Rising AntiVirus 2008/2009/2010 - Local Privilege Escalation
CVE-2010-1591localwindows28 Jan 2010
Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, incl
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component jVideoDirect - Blind SQL Injection
CVE-2010-0803webappsphp28 Jan 2010
SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
Novaboard 1.1.2 - SQL Injection
CVE-2010-0608webappsphp28 Jan 2010
SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
Geo++ GNCASTER 1.4.0.7 NMEA-data - Denial of Service
CVE-2010-0553doslinux27 Jan 2010
Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) an
23RISK
open
Exploit-DBVexDay Proof
iOS Serversman 3.1.5 - HTTP Remote Denial of Service
CVE-2010-0496dosios27 Jan 2010
FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a deni
23RISK
open
Exploit-DBVexDay Proof
Geo++ GNCASTER 1.4.0.7 - GET Denial of Service
CVE-2010-0552doslinux27 Jan 2010
Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly
23RISK
open
Exploit-DBVexDay Proof
IBM DB2 - 'REPEAT()' Local Heap Buffer Overflow
CVE-2010-0462localunix27 Jan 2010
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated use
23RISK
open
Exploit-DBVexDay Proof
PostgreSQL - 'bitsubstr' Buffer Overflow
CVE-2010-0442doslinux27 Jan 2010
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated
28RISK
open
Exploit-DB
South River Technologies WebDrive Service 9.02 build 2232 - Bad Security Descriptor Privilege Escalation
CVE-2009-4606localwindows26 Jan 2010
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which all
23RISK
open
Exploit-DBVexDay Proof
Cisco Secure Desktop 3.x - 'translation' Cross-Site Scripting
CVE-2010-0440remotehardware26 Jan 2010
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions bef
23RISK
open
Exploit-DB
Joomla! Component com_mochigames - SQL Injection
CVE-2010-0459webappswindows24 Jan 2010
SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! al
23RISK
open
Exploit-DBVexDay Proof
magic-portal 2.1 - SQL Injection
CVE-2010-0457webappsphp23 Jan 2010
SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DB
Joomla! Component com_casino - SQL Injection
CVE-2010-0461webappsphp23 Jan 2010
SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbi
23RISK
open
previouspage 398 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.