Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6041webappsphp28 Feb 2014
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6042webappsphp28 Feb 2014
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo befor
23RISK
open
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6043webappsphp28 Feb 2014
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attem
23RISK
open
Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
CVE-2014-9304webappsmultiple28 Feb 2014
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e
23RISK
open
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1907webappsphp28 Feb 2014
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor
28RISK
open
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1908webappsphp28 Feb 2014
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li
23RISK
open
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
CVE-2014-100029webappsphp27 Feb 2014
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RISK
open
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
CVE-2014-100030webappsphp27 Feb 2014
Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remot
23RISK
open
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
CVE-2014-100031webappsphp27 Feb 2014
Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5015remotewindows26 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DB
Piwigo 2.6.1 - Cross-Site Request Forgery
CVE-2014-4613webappsphp26 Feb 2014
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5014remotewindows26 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
POSH 3.1.x - 'addtoapplication.php' SQL Injection
CVE-2014-2211webappsphp26 Feb 2014
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows
23RISK
open
Exploit-DB
Technicolor TC7200 - Credentials Disclosure
CVE-2014-1677webappshardware25 Feb 2014
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
28RISK
open
Exploit-DBVexDay Proof
Sendy 1.1.8.4 - SQL Injection
CVE-2014-100012webappsphp25 Feb 2014
SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
Exploit-DB
Python - 'socket.recvfrom_into()' Remote Buffer Overflow
CVE-2014-1912remotelinux24 Feb 2014
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.
28RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5014remotewindows23 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5015remotewindows23 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (2)
CVE-2013-5019remotewindows22 Feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open
Exploit-DBVexDay Proof
SolidWorks Workgroup PDM 2014 SP2 - Arbitrary File Write
CVE-2014-100015remotewindows22 Feb 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RISK
open
Exploit-DBVexDay Proof
ATutor - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
CVE-2014-2091webappsphp22 Feb 2014
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote auth
23RISK
open
Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
CVE-2014-2089webappsphp22 Feb 2014
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .
23RISK
open
Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
CVE-2014-2090webappsphp22 Feb 2014
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inje
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection
CVE-2014-1854webappsphp22 Feb 2014
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p
23RISK
open
Exploit-DBVexDay Proof
eshtery CMS - 'FileManager.aspx' Local File Disclosure
CVE-2014-2069webappsasp22 Feb 2014
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname
28RISK
open
Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
CVE-2014-2088webappsphp22 Feb 2014
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - Remote Buffer Overflow
CVE-2013-4730remotewindows20 Feb 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DB
Stark CRM 1.0 - Multiple Vulnerabilities
CVE-2014-10008webappsphp20 Feb 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authent
23RISK
open
Exploit-DB
Stark CRM 1.0 - Multiple Vulnerabilities
CVE-2014-10009webappsphp20 Feb 2014
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
CVE-2014-2072remotemultiple19 Feb 2014
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RISK
open
previouspage 234 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.