Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
PHP DateTime - Use-After-Free
CVE-2015-0273dosphp23 Feb 2015
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x befo
35RISK
open
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2183webappsphp23 Feb 2015
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RISK
open
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2184webappsphp23 Feb 2015
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RISK
open
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2143webappsphp23 Feb 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RISK
open
Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
CVE-2015-2198webappsphp23 Feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RISK
open
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2010-5322webappsphp23 Feb 2015
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2182webappsphp23 Feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DB
Samsung iPOLiS 1.12.2 - iPOLiS XnsSdkDeviceIpInstaller ActiveX WriteConfigValue (PoC)
CVE-2015-0555doswindows22 Feb 2015
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote
23RISK
open
Exploit-DB
Piwigo 2.7.3 - SQL Injection
CVE-2015-1517webappsphp19 Feb 2015
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RISK
open
Exploit-DBVexDay Proof
Publish-It 3.6d - Local Buffer Overflow (SEH)
CVE-2014-0980localwindows18 Feb 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Exploit-DB
WordPress Plugin Duplicator 0.5.8 - Privilege Escalation
CVE-2014-9262webappsphp18 Feb 2015
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
23RISK
open
Exploit-DBVexDay Proof
Java JMX - Server Insecure Configuration Java Code Execution (Metasploit)
CVE-2015-2342remotejava17 Feb 2015
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RISK
open
Exploit-DB
eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities
CVE-2015-2071webappsphp16 Feb 2015
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows r
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site Scripting
CVE-2015-1494webappsphp16 Feb 2015
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RISK
open
Exploit-DB
WordPress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting
CVE-2015-2199webappsphp16 Feb 2015
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote
23RISK
open
Exploit-DB
WordPress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting
CVE-2015-2218webappsphp16 Feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo
23RISK
open
Exploit-DB
eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities
CVE-2015-2070webappsphp16 Feb 2015
SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitra
23RISK
open
Exploit-DB
PCMan FTP Server 2.0.7 - 'MKD' Remote Buffer Overflow
CVE-2013-4730remotewindows14 Feb 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection
CVE-2015-2196webappsphp13 Feb 2015
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ
43RISK
open
Exploit-DB
Exponent CMS 2.3.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2014-8690webappsphp12 Feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RISK
open
Exploit-DB
WordPress Plugin Video Gallery 2.7.0 - SQL Injection
CVE-2014-9097webappsphp12 Feb 2015
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RISK
open
Exploit-DB
WordPress Plugin Video Gallery 2.7.0 - SQL Injection
CVE-2015-2065webappsphp12 Feb 2015
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RISK
open
Exploit-DB
IBM Endpoint Manager - Persistent Cross-Site Scripting
CVE-2014-6137webappscgi11 Feb 2015
Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229
23RISK
open
Exploit-DBVexDay Proof
SixApart MovableType < 5.2.12 - Storable Perl Code Execution (Metasploit)
CVE-2015-1592webappslinux11 Feb 2015
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RISK
open
Exploit-DB
WordPress Plugin Survey and Poll 1.1 - Blind SQL Injection
CVE-2015-2090webappsphp11 Feb 2015
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo
23RISK
open
Exploit-DBVexDay Proof
WordPress Theme Holding Pattern - Arbitrary File Upload (Metasploit)
CVE-2015-1172webappslinux11 Feb 2015
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RISK
open
Exploit-DB
SoftSphere DefenseWall FW/IPS 3.24 - Local Privilege Escalation
CVE-2015-1515localwindows11 Feb 2015
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit)
CVE-2014-9308webappsphp10 Feb 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISK
open
Exploit-DB
RedaxScript CMS 2.2.0 - SQL Injection
CVE-2015-1518webappsphp09 Feb 2015
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RISK
open
Exploit-DB
u5CMS 3.9.3 - Multiple Persistent Cross-Site Scripting / Reflected Cross-Site Scripting Vulnerabilities
CVE-2015-1575webappsphp09 Feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web
23RISK
open
previouspage 201 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.