Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
KingView 6.53 - 'SuperGrid' Insecure ActiveX Control
CVE-2013-6127localwindows04 Sep 2013
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53
28RISK
open
Exploit-DBVexDay Proof
KingView 6.53 - 'KChartXY' ActiveX File Creation / Overwrite
CVE-2013-6128localwindows04 Sep 2013
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 doe
23RISK
open
Exploit-DBVexDay Proof
HP LoadRunner - lrFileIOService ActiveX WriteFileString Remote Code Execution (Metasploit)
CVE-2013-4798remotewindows04 Sep 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.8.4 - Local Privilege Escalation
CVE-2013-1775localosx30 Aug 2013
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4980doshardware29 Aug 2013
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RISK
open
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4982doshardware29 Aug 2013
AVTECH AVN801 DVR has a security bypass via the administration login captcha
43RISK
open
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4981doshardware29 Aug 2013
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RISK
open
Exploit-DBVexDay Proof
HP LoadRunner - lrFileIOService ActiveX Remote Code Execution (Metasploit)
CVE-2013-2370remotewindows29 Aug 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RISK
open
Exploit-DBVexDay Proof
VMware - Setuid VMware-mount Unsafe popen(3) (Metasploit)
CVE-2013-1662locallinux29 Aug 2013
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox - XMLSerializer Use-After-Free (Metasploit)
CVE-2013-0753remotewindows29 Aug 2013
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox b
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - Sudo Password Bypass (Metasploit)
CVE-2013-1775localosx29 Aug 2013
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RISK
open
Exploit-DBVexDay Proof
Aloaha PDF Suite - Remote Stack Buffer Overflow
CVE-2013-4978remotewindows28 Aug 2013
Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
cm3 Acora CMS - 'top.aspx' Information Disclosure
CVE-2013-4727webappsphp26 Aug 2013
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at
23RISK
open
Exploit-DBVexDay Proof
Oracle Endeca Server - Remote Command Execution (Metasploit)
CVE-2013-3763remotewindows26 Aug 2013
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows rem
50RISK
open
Exploit-DBVexDay Proof
Winamp 5.63 - 'winamp.ini' Local Overflow
CVE-2013-4694localwindows26 Aug 2013
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RISK
open
Exploit-DBVexDay Proof
SearchBlox - Multiple Information Disclosure Vulnerabilities
CVE-2013-3597webappsjava23 Aug 2013
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords v
23RISK
open
Exploit-DBVexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-4423webappsphp22 Aug 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-3918webappsphp22 Aug 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Exploit-DBVexDay Proof
VMware - Setuid VMware-mount Popen lsb_release Privilege Escalation
CVE-2013-1662locallinux22 Aug 2013
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RISK
open
Exploit-DBVexDay Proof
Foreman (RedHat OpenStack/Satellite) - users/create Mass Assignment (Metasploit)
CVE-2013-2113webappslinux22 Aug 2013
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users w
43RISK
open
Exploit-DBVexDay Proof
Xibo - 'layout' HTML Injection
CVE-2013-4888webappsphp21 Aug 2013
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
Xibo - Cross-Site Request Forgery
CVE-2013-4889webappsphp21 Aug 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attac
23RISK
open
Exploit-DBVexDay Proof
Graphite Web - Unsafe Pickle Handling (Metasploit)
CVE-2013-5093remoteunix21 Aug 2013
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python
50RISK
open
Exploit-DBVexDay Proof
Twilight CMS - DeWeS Web Server Directory Traversal
CVE-2013-4900webappsphp21 Aug 2013
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote
23RISK
open
Exploit-DBVexDay Proof
Java - 'storeImageArray()' Invalid Array Indexing (Metasploit)
CVE-2013-2465CRITICALunder attackransomwareremotemultiple19 Aug 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 U
100RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'STOR' Remote Buffer Overflow
CVE-2013-4730remotewindows19 Aug 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.0.8 - '.m3u' Local Crash (PoC)
CVE-2013-6283doswindows19 Aug 2013
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
23RISK
open
Exploit-DBVexDay Proof
AlgoSec Firewall Analyzer - Cross-Site Scripting
CVE-2013-5092remotehardware16 Aug 2013
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
Chasys Draw IES - Local Buffer Overflow (Metasploit)
CVE-2013-3928localwindows15 Aug 2013
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote atta
50RISK
open
Exploit-DBVexDay Proof
DotNetNuke DNNArticle Module 10.0 - SQL Injection
CVE-2013-5117webappsphp15 Aug 2013
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNu
23RISK
open
previouspage 100 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.