Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7247webappshardware24 Jan 2014
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows
23RISK
open
Exploit-DB
Joomla! Component Komento 1.7.2 - Persistent Cross-Site Scripting
CVE-2014-0793webappsphp24 Jan 2014
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RISK
open
Exploit-DBVexDay Proof
Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution
CVE-2014-1683webappsphp24 Jan 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RISK
open
Exploit-DB
MW6 Technologies MaxiCode - ActiveX 'Data' Buffer Overflow (PoC)
CVE-2013-6040HIGHdoswindows24 Jan 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RISK
open
Exploit-DB
Ammyy Admin 3.2 - Authentication Bypass
CVE-2013-5581localwindows24 Jan 2014
20RISK
open
Exploit-DB
MW6 Technologies Datamatrix - ActiveX 'Data' Buffer Overflow
CVE-2013-6040HIGHdoswindows24 Jan 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RISK
open
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Directory Traversal (Metasploit)
CVE-2013-6194remotewindows24 Jan 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RISK
open
Exploit-DB
Joomla! Component JV Comment 3.0.2 - 'id' SQL Injection
CVE-2014-0794webappsphp24 Jan 2014
SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authentic
23RISK
open
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 Jan 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RISK
open
Exploit-DBVexDay Proof
Daum Game 1.1.0.5 - ActiveX 'IconCreate Method' Remote Stack Buffer Overflow
CVE-2013-7246remotewindows24 Jan 2014
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows
28RISK
open
Exploit-DB
MW6 Technologies Aztec - ActiveX 'Data' Buffer Overflow (PoC)
CVE-2013-6040HIGHdoswindows24 Jan 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RISK
open
Exploit-DBVexDay Proof
GoToMeeting for Android - Multiple Local Information Disclosure Vulnerabilities
CVE-2014-1664localandroid23 Jan 2014
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a
23RISK
open
Exploit-DB
Simple E-document 1.31 - Authentication Bypass
CVE-2014-10020webappsphp23 Jan 2014
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
CVE-2014-100020webappsphp23 Jan 2014
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
CVE-2008-0685webappsphp23 Jan 2014
SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
MuPDF 1.3 - 'xps_parse_color()' Stack Buffer Overflow
CVE-2014-2013localwindows20 Jan 2014
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote a
28RISK
open
Exploit-DB
Teracom Modem T2-B-Gawv1.4U10Y-BI - Persistent Cross-Site Scripting
CVE-2014-10018webappshardware20 Jan 2014
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RISK
open
Exploit-DB
ASUS RT-N56U - Remote Buffer Overflow (ROP)
CVE-2013-6343remotehardware19 Jan 2014
Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection
CVE-2013-7219webappsphp16 Jan 2014
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a
23RISK
open
Exploit-DB
Collabtive 1.1 - 'managetimetracker.php' SQL Injection
CVE-2013-6872webappsphp15 Jan 2014
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu
23RISK
open
Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
CVE-2014-10015webappsphp14 Jan 2014
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to exe
23RISK
open
Exploit-DB
Horizon QCMS 4.0 - Multiple Vulnerabilities
CVE-2013-7139webappsphp14 Jan 2014
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows rem
23RISK
open
Exploit-DB
Conceptronic Wireless Pan & Tilt Network Camera - Cross-Site Request Forgery
CVE-2013-7204webappshardware14 Jan 2014
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21
28RISK
open
Exploit-DBVexDay Proof
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
CVE-2013-2251CRITICALunder attackwebappsmultiple14 Jan 2014
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open
Exploit-DB
SoapUI 4.6.3 - Remote Code Execution
CVE-2014-1202remotewindows14 Jan 2014
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c
23RISK
open
Exploit-DBVexDay Proof
Oracle Supply Chain Products Suite - Remote Security
CVE-2013-5880remotemultiple14 Jan 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RISK
open
Exploit-DB
Linux Kernel (Ubuntu 11.10/12.04) - binfmt_script Stack Data Disclosure
CVE-2012-4530doslinux14 Jan 2014
The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, whic
23RISK
open
Exploit-DBVexDay Proof
SerComm Device - Remote Code Execution (Metasploit)
CVE-2014-0659remotehardware14 Jan 2014
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RISK
open
Exploit-DB
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
CVE-2014-10001webappsphp14 Jan 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attacker
23RISK
open
Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
CVE-2014-10014webappsphp14 Jan 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attacke
23RISK
open
previouspage 237 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.