Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection
CVE-2015-5082remotecgi29 Jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RISK
open
Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
CVE-2015-4553webappsphp29 Jun 2015
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RISK
open
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
CVE-2005-2112webappsphp29 Jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RISK
open
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
CVE-2005-2113webappsphp29 Jun 2015
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote att
23RISK
open
Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection (Metasploit)
CVE-2015-5082remotecgi29 Jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RISK
open
Exploit-DBVexDay Proof
Havij - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHunder attackremotewindows27 Jun 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
CVE-2015-3443webappsmultiple26 Jun 2015
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RISK
open
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4630webappsphp26 Jun 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RISK
open
Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
CVE-2015-4633webappsphp26 Jun 2015
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RISK
open
Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
CVE-2015-2169webappswindows26 Jun 2015
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RISK
open
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4631webappsphp26 Jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RISK
open
Exploit-DB
Koha 3.20.1 - Directory Traversal
CVE-2015-4632webappsphp26 Jun 2015
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RISK
open
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-3221webappsphp24 Jun 2015
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
CVE-2015-1701HIGHunder attackransomwarelocalwindows24 Jun 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open
Exploit-DBVexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
CVE-2015-4117webappsphp24 Jun 2015
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
CVE-2015-3090remotemultiple24 Jun 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RISK
open
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-5066webappsphp24 Jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RISK
open
Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
CVE-2015-3933webappsphp24 Jun 2015
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RISK
open
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3112doswindows23 Jun 2015
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RISK
open
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
CVE-2015-3110doswindows23 Jun 2015
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RISK
open
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3111doswindows23 Jun 2015
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RISK
open
Exploit-DBVexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
CVE-2015-1158remotemultiple22 Jun 2015
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RISK
open
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5150webappsmultiple19 Jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RISK
open
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5149webappsmultiple19 Jun 2015
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RISK
open
Exploit-DBVexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
CVE-2007-3071webappswindows19 Jun 2015
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RISK
open
Exploit-DBVexDay Proof
Lively Cart - SQL Injection
CVE-2015-5148webappsmultiple19 Jun 2015
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RISK
open
Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
CVE-2015-5079webappsphp17 Jun 2015
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RISK
open
Exploit-DB
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
CVE-2015-2803webappsphp16 Jun 2015
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
CVE-2015-1328locallinux16 Jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-1328locallinux16 Jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
previouspage 191 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.