Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Visual Mining NetCharts Server - Remote Code Execution (Metasploit)
CVE-2014-8516remotejava10 Nov 2014
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co
60RISK
open
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8604webappsphp10 Nov 2014
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th
23RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7866webappsjsp10 Nov 2014
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and
45RISK
open
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9004webappsphp10 Nov 2014
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7868webappsjsp10 Nov 2014
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RISK
open
Exploit-DB
PHP-Fusion 7.02.07 - SQL Injection
CVE-2014-8596webappsphp10 Nov 2014
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9005webappsphp10 Nov 2014
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7868webappsmultiple09 Nov 2014
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6035webappsmultiple09 Nov 2014
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier al
28RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6036webappsmultiple09 Nov 2014
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Socia
35RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6034webappsmultiple09 Nov 2014
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in Z
60RISK
open
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7866webappsmultiple09 Nov 2014
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and
45RISK
open
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3439webappsjsp06 Nov 2014
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitr
23RISK
open
Exploit-DBVexDay Proof
Belkin N750 - 'jump?login' Remote Buffer Overflow
CVE-2014-1635remotehardware06 Nov 2014
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISK
open
Exploit-DBVexDay Proof
Citrix Netscaler SOAP Handler - Remote Code Execution (Metasploit)
CVE-2014-7140remotebsd06 Nov 2014
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetS
28RISK
open
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3437webappsjsp06 Nov 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read ar
23RISK
open
Exploit-DBVexDay Proof
X7 Chat 2.0.5 - 'message.php' PHP Code Execution (Metasploit)
CVE-2014-8998remotephp06 Nov 2014
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3438webappsjsp06 Nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager
23RISK
open
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8773webappsphp05 Nov 2014
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mec
23RISK
open
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8774webappsphp05 Nov 2014
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attacke
23RISK
open
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8775webappsphp05 Nov 2014
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, whic
23RISK
open
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2)
CVE-2014-6038webappsmultiple05 Nov 2014
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili
60RISK
open
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2)
CVE-2014-6039webappsmultiple05 Nov 2014
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio
50RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7196webappsphp03 Nov 2014
20RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-6271CRITICALunder attackwebappsphp03 Nov 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7169CRITICALunder attackwebappsphp03 Nov 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
CVE-2014-3704webappsphp03 Nov 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-62771webappsphp03 Nov 2014
20RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7227webappsphp03 Nov 2014
20RISK
open
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-3671webappsphp03 Nov 2014
20RISK
open
previouspage 210 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.