Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1486remotewindows_x8618 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1489remotewindows_x8618 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RISK
open
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-8008webappsmultiple18 Aug 2015
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manage
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1487remotewindows_x8618 Aug 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RISK
open
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-6271CRITICALunder attackwebappsmultiple18 Aug 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
CVE-2014-6332HIGHunder attackremotewindows17 Aug 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2015-1830remotewindows17 Aug 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RISK
open
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2016-3088CRITICALunder attackremotewindows17 Aug 2015
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
Exploit-DB
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
CVE-2015-4495HIGHunder attacklocalmultiple15 Aug 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISK
open
Exploit-DB
Google Chrome 43.0 - Certificate MIME Handling Integer Overflow
CVE-2015-1265dosmultiple13 Aug 2015
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
CVE-2015-5161webappsmultiple13 Aug 2015
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RISK
open
Exploit-DB
Microsoft Windows 8.1 - DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-076)
CVE-2015-2370localwindows13 Aug 2015
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RISK
open
Exploit-DB
Microsoft Windows Server 2003 SP2 - TCP/IP IOCTL Privilege Escalation (MS14-070)
CVE-2014-4076localwindows12 Aug 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RISK
open
Exploit-DB
Microsoft Internet Explorer - CTreeNode::GetCascadedLang Use-After-Free (MS15-079)
CVE-2015-2444doswindows12 Aug 2015
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
Exploit-DB
Dell Netvault Backup 10.0.1.24 - Denial of Service
CVE-2015-5696doswindows07 Aug 2015
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
23RISK
open
Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
CVE-2013-5065HIGHunder attacklocalwindows_x8607 Aug 2015
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISK
open
Exploit-DB
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
CVE-2015-2321webappsphp07 Aug 2015
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RISK
open
Exploit-DB
Linux Kernel - 'espfix64' Nested NMIs Interrupting Privilege Escalation
CVE-2015-3290locallinux_x86-6405 Aug 2015
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during n
23RISK
open
Exploit-DB
ISC BIND 9 - TKEY Remote Denial of Service (PoC)
CVE-2015-5477dosmultiple05 Aug 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
Exploit-DBVexDay Proof
ISC BIND 9 - TKEY (PoC)
CVE-2015-5477dosmultiple01 Aug 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISK
open
Exploit-DBVexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
CVE-2015-5602locallinux28 Jul 2015
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4667webappsphp27 Jul 2015
Multiple hardcoded credentials in Xsuite 2.x.
28RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4666webappsphp27 Jul 2015
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack
43RISK
open
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3246doslinux27 Jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4664webappsphp27 Jul 2015
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RISK
open
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3245doslinux27 Jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4665webappsphp27 Jul 2015
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RISK
open
Exploit-DB
WordPress Plugin Count Per Day 3.4 - SQL Injection
CVE-2015-5533webappsphp27 Jul 2015
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4668webappsphp27 Jul 2015
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RISK
open
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4669webappsphp27 Jul 2015
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy
23RISK
open
previouspage 188 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.