Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Incredible PBX 2.0.6.5.0 - Remote Command Execution
CVE-2014-9001webappsphp27 Oct 2014
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via s
23RISK
open
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8654webappshardware27 Oct 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wirele
23RISK
open
Exploit-DBVexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
CVE-2014-2647webappsmultiple27 Oct 2014
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISK
open
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8656webappshardware27 Oct 2014
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d
28RISK
open
Exploit-DB
WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection
CVE-2014-8586webappsphp27 Oct 2014
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RISK
open
Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
CVE-2014-4114HIGHunder attackremotewindows25 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
CVE-2014-6352HIGHunder attackremotewindows25 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
CVE-2014-8739webappsphp25 Oct 2014
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
Exploit-DB
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
CVE-2014-8770webappsphp25 Oct 2014
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RISK
open
Exploit-DB
Dell EqualLogic Storage - Directory Traversal
CVE-2013-3304webappshardware25 Oct 2014
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary
23RISK
open
Exploit-DB
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
CVE-2013-7057webappsphp23 Oct 2014
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to
23RISK
open
Exploit-DB
iBackup 10.0.0.32 - Local Privilege Escalation
CVE-2014-5507localwindows22 Oct 2014
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
CVE-2014-7228remotephp21 Oct 2014
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RISK
open
Exploit-DBVexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
CVE-2014-4872remotewindows21 Oct 2014
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISK
open
Exploit-DBVexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
CVE-2011-1485locallinux20 Oct 2014
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RISK
open
Exploit-DB
Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow
CVE-2014-8322remotelinux20 Oct 2014
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows_x8620 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
CVE-2014-6352HIGHunder attacklocalwindows20 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows_x8620 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
CVE-2014-4114HIGHunder attacklocalwindows20 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
CVE-2014-0995doswindows17 Oct 2014
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
CVE-2014-3704webappsphp17 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
CVE-2014-3704webappsphp17 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
CVE-2014-3704webappsphp16 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
CVE-2014-4971localwindows_x8615 Oct 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISK
open
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828webappslinux15 Oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISK
open
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3829webappslinux15 Oct 2014
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RISK
open
Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2014-8577webappsphp14 Oct 2014
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
YourMembers Plugin - Blind SQL Injection
CVE-2014-100003webappsphp14 Oct 2014
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISK
open
Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
CVE-2014-7281webappshardware14 Oct 2014
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RISK
open
previouspage 212 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.