Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DB
Zoph 0.9.1 - Multiple Vulnerabilities
CVE-2014-9235webappsphp17 Nov 2014
Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated
23RISK
open
Exploit-DB
.NET Remoting Services - Remote Command Execution
CVE-2014-1806remotewindows17 Nov 2014
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not pr
35RISK
open
Exploit-DB
Zoph 0.9.1 - Multiple Vulnerabilities
CVE-2014-9236webappsphp17 Nov 2014
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier al
23RISK
open
Exploit-DB
Maarch LetterBox 2.8 - (Authentication Bypass) Insecure Cookies
CVE-2014-8995webappsphp17 Nov 2014
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us
23RISK
open
Exploit-DB
clientResponse Client Management 4.1 - Cross-Site Scripting
CVE-2014-100013webappsmultiple15 Nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
OSSEC 2.8 - 'hosts.deny' Local Privilege Escalation
CVE-2014-5284locallinux14 Nov 2014
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi
23RISK
open
Exploit-DB
Gogs - 'users'/'repos' '?q' SQL Injection
CVE-2014-8682webappsmultiple14 Nov 2014
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISK
open
Exploit-DB
Gogs - 'label' SQL Injection
CVE-2014-8681webappsmultiple14 Nov 2014
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
MyBB 1.8.x - Multiple Vulnerabilities
CVE-2014-9240webappsphp13 Nov 2014
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
CVE-2014-8997webappsphp13 Nov 2014
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RISK
open
Exploit-DB
Proticaret E-Commerce Script 3.0 - SQL Injection (1)
CVE-2014-9237webappsmultiple13 Nov 2014
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a
23RISK
open
Exploit-DB
MyBB 1.8.x - Multiple Vulnerabilities
CVE-2014-9241webappsphp13 Nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
CVE-2014-6332HIGHunder attackremotewindows13 Nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DB
F5 BIG-IP 10.1.0 - Directory Traversal
CVE-2014-8727webappsjsp13 Nov 2014
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RISK
open
Exploit-DB
Microsoft Internet Explorer < 11 - OLE Automation Array Remote Code Execution (Metasploit)
CVE-2014-6332HIGHunder attackremotewindows13 Nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DB
Piwigo 2.6.0 - 'picture.php?rate' SQL Injection
CVE-2014-9115webappsphp13 Nov 2014
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x
23RISK
open
Exploit-DB
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
CVE-2014-4114HIGHunder attacklocalwindows12 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
CVE-2014-6352HIGHunder attacklocalwindows12 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
WordPress Plugin SupportEzzy Ticket System 1.2.5 - Persistent Cross-Site Scripting
CVE-2014-9179webappsphp12 Nov 2014
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe
23RISK
open
Exploit-DB
Subex Fms 7.4 - SQL Injection
CVE-2014-8728webappsmultiple11 Nov 2014
SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System a
23RISK
open
Exploit-DB
WordPress Plugin Photo Gallery 1.2.5 - Unrestricted Arbitrary File Upload
CVE-2014-9312webappsphp11 Nov 2014
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RISK
open
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8606webappsphp10 Nov 2014
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ
23RISK
open
Exploit-DBVexDay Proof
phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2014-8954webappsphp10 Nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8604webappsphp10 Nov 2014
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th
23RISK
open
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9004webappsphp10 Nov 2014
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DB
Password Manager Pro / Pro MSP - Blind SQL Injection
CVE-2014-8498webappsmultiple10 Nov 2014
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager P
28RISK
open
previouspage 210 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.