Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DB
WebGate eDVR Manager 2.6.4 - SiteName Stack Overflow
CVE-2015-2098remotewindows27 Mar 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RISK
open
Exploit-DB
WebGate Control Center 4.8.7 - GetThumbnail Stack Overflow
CVE-2015-2099remotewindows27 Mar 2015
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec
28RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 Mar 2015
20RISK
open
Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
CVE-2015-2295webappsphp26 Mar 2015
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
CVE-2015-2097remotewindows26 Mar 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 Mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
CVE-2009-1646localwindows26 Mar 2015
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 Mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 Mar 2015
20RISK
open
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotehardware26 Mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9014webappsphp25 Mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9013webappsphp25 Mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISK
open
Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
CVE-2015-0313HIGHunder attackremotewindows25 Mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
CVE-2014-8636remotemultiple24 Mar 2015
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RISK
open
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
CVE-2011-5165localwindows22 Mar 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9014webappsphp22 Mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISK
open
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9013webappsphp22 Mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISK
open
Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
CVE-2014-5144webappsphp21 Mar 2015
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RISK
open
Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
CVE-2015-0514webappsjava19 Mar 2015
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RISK
open
previouspage 199 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.