Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,447cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 Mar 2015
20RISK
open
Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
CVE-2015-2097remotewindows26 Mar 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
CVE-2015-2295webappsphp26 Mar 2015
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 Mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 Mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 Mar 2015
20RISK
open
Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
CVE-2015-0313HIGHunder attackremotewindows25 Mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9014webappsphp25 Mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9013webappsphp25 Mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
CVE-2014-8636remotemultiple24 Mar 2015
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RISK
open
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
CVE-2011-5165localwindows22 Mar 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9013webappsphp22 Mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9014webappsphp22 Mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISK
open
Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
CVE-2014-5144webappsphp21 Mar 2015
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RISK
open
Exploit-DB
Citrix Command Center - Credential Disclosure
CVE-2015-2682webappsxml19 Mar 2015
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RISK
open
Exploit-DB
Citrix Nitro SDK - Command Injection
CVE-2015-2838webappslinux19 Mar 2015
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RISK
open
Exploit-DBVexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
CVE-2014-7236remotephp19 Mar 2015
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RISK
open
Exploit-DB
Joomla! Component ECommerce-WD 1.2.5 - SQL Injection
CVE-2015-2562webappsphp19 Mar 2015
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RISK
open
previouspage 198 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.