Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - 'pagesUTF8/Sys_DirAnzeige.jsp?Pfad' Direct Request Information Disclosure
CVE-2009-0700webappsjsp07 Jan 2009
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens
23RISK
open
Exploit-DBVexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0829webappsphp07 Jan 2009
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
Multiple CA Service Management Products - Remote Command Execution
CVE-2009-0043remotewindows07 Jan 2009
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not pro
35RISK
open
Exploit-DBVexDay Proof
Plunet BusinessManager 4.1 - '/pagesUTF8/auftrag_allgemeinauftrag.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2009-0699webappsjsp07 Jan 2009
Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear
23RISK
open
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.REMOVEWORKSPACE SQL Injection
CVE-2008-3984localmultiple06 Jan 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open
Exploit-DBVexDay Proof
Oracle 10g - SYS.LT.MERGEWORKSPACE SQL Injection
CVE-2008-3983localmultiple06 Jan 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISK
open
Exploit-DBVexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0121webappsphp06 Jan 2009
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)
CVE-2009-3429localwindows04 Jan 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows03 Jan 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow
CVE-2009-3429localwindows03 Jan 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Destiny Media Player 1.61 - '.m3u' Local Buffer Overflow (PoC)
CVE-2009-3429doswindows02 Jan 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
PHP 5.2.8 gd library - 'imageRotate()' Information Leak
CVE-2008-5498localmultiple02 Jan 2009
Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the co
23RISK
open
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6758webappsphp01 Jan 2009
Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att
23RISK
open
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (2)
CVE-2008-5821dososx01 Jan 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RISK
open
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0710webappsphp01 Jan 2009
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Apple Safari 3.2 WebKit - 'alink' Property Memory Leak Remote Denial of Service (1)
CVE-2008-5821dososx01 Jan 2009
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RISK
open
Exploit-DBVexDay Proof
Megacubo 5.0.7 - 'mega://' Arbitrary File Download and Execute
CVE-2008-6748remotewindows01 Jan 2009
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RISK
open
Exploit-DBVexDay Proof
PHPFootball 1.6 - Remote Hash Disclosure
CVE-2009-0709webappsphp01 Jan 2009
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
Viart shopping cart 3.5 - Multiple Vulnerabilities
CVE-2008-6765webappsphp01 Jan 2009
ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a mo
23RISK
open
Exploit-DBVexDay Proof
Audio File Library 0.2.6 - libaudiofile 'msadpcm.c .WAV' File Processing Buffer Overflow
CVE-2008-5824remotelinux30 Dec 2008
Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Media Player 9/10/11 - '.WAV' File Parsing Code Execution
CVE-2008-5745remotewindows29 Dec 2008
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RISK
open
Exploit-DBVexDay Proof
ViArt Shop 3.5 - 'manuals_search.php?manuals_search' Cross-Site Scripting
CVE-2008-6757webappsphp29 Dec 2008
Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attac
23RISK
open
Exploit-DBVexDay Proof
xterm - DECRQSS Remote Command Execution
CVE-2006-7236remotelinux29 Dec 2008
The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, whic
23RISK
open
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-4584remotewindows28 Dec 2008
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RISK
open
Exploit-DBVexDay Proof
Miniweb 2.0 - Authentication Bypass
CVE-2008-2197webappsphp28 Dec 2008
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Chilkat FTP - ActiveX (SaveLastError) Insecure Method
CVE-2008-1647remotewindows28 Dec 2008
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5875webappsphp24 Dec 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5865webappsphp24 Dec 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5864webappsphp24 Dec 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2009-2953doswindows23 Dec 2008
Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption)
23RISK
open
previouspage 459 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.