Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
CVE-2009-0520remoteunix24 Feb 2009
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RISK
open
Exploit-DBVexDay Proof
Joomla! / Mambo Component gigCalendar 1.0 - 'banddetails.php' SQL Injection
CVE-2009-0730webappsphp23 Feb 2009
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_q
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 Feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 Feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows20 Feb 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'sock.c' SO_BSDCOMPAT Option Information Disclosure
CVE-2009-0676locallinux20 Feb 2009
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct
23RISK
open
Exploit-DBVexDay Proof
Enomaly ECP / Enomalism < 2.2.1 - Multiple Local Vulnerabilities
CVE-2009-0390localmultiple16 Feb 2009
Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows lo
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'make_indexed_dir()' Local Denial of Service
CVE-2009-0746doslinux16 Feb 2009
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7
23RISK
open
Exploit-DBVexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
CVE-2009-0659doswindows16 Feb 2009
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown
23RISK
open
Exploit-DBVexDay Proof
MySQL 6.0.9 - XPath Expression Remote Denial of Service
CVE-2009-0819doslinux14 Feb 2009
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial
28RISK
open
Exploit-DBVexDay Proof
CmsFaethon 2.2.0 - 'item' SQL Injection
CVE-2009-5094webappsphp13 Feb 2009
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
ea-gBook 0.1 - Remote Command Execution / Remote File Inclusion
CVE-2009-5095webappsphp13 Feb 2009
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
CVE-2009-5088webappsphp13 Feb 2009
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
Vlinks 1.1.6 - 'id' SQL Injection
CVE-2009-5091webappsphp13 Feb 2009
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
CVE-2009-5089webappsphp13 Feb 2009
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RISK
open
Exploit-DBVexDay Proof
Poppler 0.10.3 - Denial of Service
CVE-2009-0755doslinux12 Feb 2009
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RISK
open
Exploit-DBVexDay Proof
Poppler 0.10.3 - Denial of Service
CVE-2009-0756doslinux12 Feb 2009
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RISK
open
Exploit-DBVexDay Proof
GeoVision Digital Video Surveillance System 8.2 - Arbitrary File Disclosure
CVE-2009-5087remotewindows11 Feb 2009
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Bloggeruniverse 2.0 Beta - 'id' SQL Injection
CVE-2009-5090webappsphp11 Feb 2009
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem
23RISK
open
Exploit-DBVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0543remotemultiple10 Feb 2009
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms vi
28RISK
open
Exploit-DBVexDay Proof
TYPO3 < 4.0.12/4.1.10/4.2.6 - 'jumpUrl' Remote File Disclosure
CVE-2009-0815webappsphp10 Feb 2009
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 befo
50RISK
open
Exploit-DBVexDay Proof
Swann DVR4 SecuraNet - Directory Traversal
CVE-2009-0640remotelinux10 Feb 2009
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re
23RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.3 - 'mod_sql' 'Username' SQL Injection
CVE-2009-0542remotemultiple10 Feb 2009
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISK
open
Exploit-DBVexDay Proof
Banking@Home 2.1 - 'login.asp' Multiple SQL Injections
CVE-2009-0741webappsasp10 Feb 2009
SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execut
23RISK
open
Exploit-DBVexDay Proof
WB News 2.1.1 - config[installdir] Remote File Inclusion
CVE-2009-0294webappsphp09 Feb 2009
Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote atta
23RISK
open
Exploit-DBVexDay Proof
FlexCMS 2.5 - 'catId' SQL Injection
CVE-2009-1256webappsphp09 Feb 2009
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISK
open
Exploit-DBVexDay Proof
Gaeste 1.6 - 'gastbuch.php' Remote File Disclosure
CVE-2009-5093webappsphp09 Feb 2009
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISK
open
Exploit-DBVexDay Proof
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-0611remotenovell09 Feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterp
23RISK
open
Exploit-DBVexDay Proof
FotoWeb 6.0 - 'Login.fwx?s' Cross-Site Scripting
CVE-2009-0573webappsphp09 Feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
FotoWeb 6.0 - 'Grid.fwx?search' Cross-Site Scripting
CVE-2009-0573webappsphp09 Feb 2009
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RISK
open
previouspage 456 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.