Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Android WiFi-Direct - Denial of Service
CVE-2014-0997dosandroid26 Jan 2015
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RISK
open
Exploit-DB
Comodo Backup 4.4.0.0 - Null Pointer Dereference Privilege Escalation
CVE-2014-9633localwindows26 Jan 2015
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha
23RISK
open
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9226webappsmultiple26 Jan 2015
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security:
23RISK
open
Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
CVE-2015-1478webappsmultiple26 Jan 2015
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attac
23RISK
open
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1374webappsphp26 Jan 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1372webappsphp26 Jan 2015
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p
23RISK
open
Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
CVE-2015-1477webappsmultiple26 Jan 2015
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execu
23RISK
open
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1373webappsphp26 Jan 2015
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inje
23RISK
open
Exploit-DB
VideoLAN VLC Media Player 2.1.5 - Write Access Violation
CVE-2014-9598localwindows26 Jan 2015
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arb
23RISK
open
Exploit-DB
ManageEngine ServiceDesk Plus 9.0 < Build 9031 - User Privileges Management
CVE-2015-1480webappsjsp26 Jan 2015
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RISK
open
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9224webappsmultiple26 Jan 2015
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management serve
23RISK
open
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1371webappsphp26 Jan 2015
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code b
23RISK
open
Exploit-DB
VideoLAN VLC Media Player 2.1.5 - DEP Access Violation
CVE-2014-9597localwindows26 Jan 2015
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to ex
23RISK
open
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9225webappsmultiple26 Jan 2015
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symante
23RISK
open
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'license.php' Remote Command Execution (Metasploit)
CVE-2012-0261webappsmultiple25 Jan 2015
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISK
open
Exploit-DB
NPDS CMS REvolution-13 - SQL Injection
CVE-2015-1400webappsphp24 Jan 2015
SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DB
ManageEngine ServiceDesk Plus 9.0 - SQL Injection
CVE-2015-1479webappsjsp22 Jan 2015
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RISK
open
Exploit-DB
Exif Pilot 4.7.2 - Buffer Overflow (SEH)
CVE-2015-1362doswindows22 Jan 2015
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open
Exploit-DB
ecommerceMajor - SQL Injection / Authentication Bypass
CVE-2015-1476webappsphp22 Jan 2015
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DB
ArticleFR CMS 3.0.5 - SQL Injection
CVE-2015-1364webappsphp21 Jan 2015
SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.
23RISK
open
Exploit-DB
Zhone GPON 2520 R4.0.2.566b - Crash (PoC)
CVE-2015-2055doshardware21 Jan 2015
Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the
23RISK
open
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1366webappsphp20 Jan 2015
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress all
23RISK
open
Exploit-DBVexDay Proof
ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2014-5301remotejava20 Jan 2015
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RISK
open
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1375webappsphp20 Jan 2015
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload
28RISK
open
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1376webappsphp20 Jan 2015
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape
CVE-2014-4492localosx20 Jan 2015
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RISK
open
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1365webappsphp20 Jan 2015
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RISK
open
Exploit-DB
Malwarebytes Anti-Exploit 1.03.1.1220/1.04.1.1012 - Out-of-Bounds Read Denial of Service
CVE-2014-100039doswindows20 Jan 2015
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a c
23RISK
open
Exploit-DB
WordPress Plugin Cforms 14.7 - Remote Code Execution
CVE-2014-9473webappsphp19 Jan 2015
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r
28RISK
open
Exploit-DB
Samsung SmartViewer BackupToAvi 3.0 - Remote Code Execution
CVE-2014-9265remotewindows19 Jan 2015
Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remo
23RISK
open
previouspage 203 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.