Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
CVE-2014-9144webappshardware04 Dec 2014
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac
23RISK
open
Exploit-DB
WordPress Plugin Google Document Embedder 2.5.16 - 'mysql_real_escpae_string' Bypass SQL Injection
CVE-2014-9173webappsphp03 Dec 2014
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RISK
open
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5446webappsmultiple03 Dec 2014
Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2
35RISK
open
Exploit-DB
BulletProof FTP Client 2010 - Local Buffer Overflow (SEH)
CVE-2014-2973localwindows03 Dec 2014
35RISK
open
Exploit-DB
WordPress Plugin Cart66 Lite eCommerce 1.5.1.17 - Blind SQL Injection
CVE-2014-9305webappsphp03 Dec 2014
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RISK
open
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5445webappsmultiple03 Dec 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RISK
open
Exploit-DBVexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
CVE-2013-1428remotemultiple02 Dec 2014
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RISK
open
Exploit-DB
tnftp (FreeBSD 8/9/10) - 'tnftp' Client Side
CVE-2014-8517remotebsd02 Dec 2014
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
CVE-2014-4404HIGHunder attacklocalosx02 Dec 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RISK
open
Exploit-DB
WordPress Plugin Nextend Facebook Connect 1.4.59 - Cross-Site Scripting
CVE-2014-8800webappsphp02 Dec 2014
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before
23RISK
open
Exploit-DB
Thomson Reuters Fixed Assets CS 13.1.4 - Local Privilege Escalation
CVE-2014-9141localwindows02 Dec 2014
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all
23RISK
open
Exploit-DB
ProjectSend r-561 - Arbitrary File Upload
CVE-2014-9567webappsphp02 Dec 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RISK
open
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-9303webappshardware02 Dec 2014
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator
23RISK
open
Exploit-DB
TYPO3 Extension ke DomPDF - Remote Code Execution
CVE-2014-6235webappsphp02 Dec 2014
Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-8868webappshardware02 Dec 2014
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain
23RISK
open
Exploit-DB
WordPress Core < 4.0.1 - Denial of Service
CVE-2014-9034dosphp01 Dec 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RISK
open
Exploit-DB
Drupal < 7.34 - Denial of Service
CVE-2014-9016dosphp01 Dec 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RISK
open
Exploit-DB
WordPress Core 4.0 - Denial of Service
CVE-2014-9034dosphp01 Dec 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RISK
open
Exploit-DB
CCH Wolters Kluwer PFX Engagement 7.1 - Local Privilege Escalation
CVE-2014-9113localwindows28 Nov 2014
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RISK
open
Exploit-DB
Elipse E3 - HTTP Denial of Service
CVE-2014-8652doswindows26 Nov 2014
Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via
23RISK
open
Exploit-DB
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 - '.wax' Local Buffer Overflow (SEH)
CVE-2014-9448localwindows26 Nov 2014
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISK
open
Exploit-DB
Android WAPPushManager - SQL Injection
CVE-2014-8507dosandroid26 Nov 2014
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
CVE-2014-9119webappsphp26 Nov 2014
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RISK
open
Exploit-DB
xEpan 1.0.1 - Cross-Site Request Forgery
CVE-2014-8429webappsphp26 Nov 2014
Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows
23RISK
open
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8425webappshardware25 Nov 2014
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the confi
23RISK
open
Exploit-DB
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
CVE-2014-3153HIGHunder attacklocallinux25 Nov 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISK
open
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8424webappshardware25 Nov 2014
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RISK
open
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8423webappshardware25 Nov 2014
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RISK
open
Exploit-DB
PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection
CVE-2014-9347webappsphp25 Nov 2014
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DB
WordPress Plugin Google Document Embedder 2.5.14 - SQL Injection
CVE-2014-9173webappsphp25 Nov 2014
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RISK
open
previouspage 207 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.