Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DB
Juniper Junos J-Web - Privilege Escalation
CVE-2013-6618webappsphp12 Nov 2013
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,
28RISK
open
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' File Local Buffer Overflow (SEH Unicode)
CVE-2013-7409localwindows12 Nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-3528webappsphp08 Nov 2013
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack
23RISK
open
Exploit-DBVexDay Proof
Vivotek IP Cameras - RTSP Authentication Bypass
CVE-2013-4985webappshardware08 Nov 2013
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RISK
open
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-2749webappsphp08 Nov 2013
20RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5220webappshardware08 Nov 2013
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device
23RISK
open
Exploit-DBVexDay Proof
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)
CVE-2013-6364webappsphp08 Nov 2013
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RISK
open
Exploit-DB
Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection
CVE-2013-6164webappsphp08 Nov 2013
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-7382remotelinux08 Nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5218webappshardware08 Nov 2013
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5037webappshardware08 Nov 2013
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4468remotelinux08 Nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5039webappshardware08 Nov 2013
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.1
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5038webappshardware08 Nov 2013
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5219webappshardware08 Nov 2013
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrar
23RISK
open
Exploit-DB
appRain 3.0.2 - Blind SQL Injection
CVE-2013-6058webappsphp08 Nov 2013
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4467remotelinux08 Nov 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RISK
open
Exploit-DBVexDay Proof
Hanso Player 2.5.0 - 'm3u' Buffer Overflow (Denial of Service)
CVE-2013-7280doswindows05 Nov 2013
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RISK
open
Exploit-DB
Apache Tomcat 5.5.25 - Cross-Site Request Forgery
CVE-2013-6357webappsmultiple04 Nov 2013
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows re
23RISK
open
Exploit-DBVexDay Proof
Google Android - Signature Verification Security Bypass
CVE-2013-6792remoteandroid04 Nov 2013
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
23RISK
open
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - Local Buffer Overflow (SEH)
CVE-2013-6935localwindows01 Nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
OpenMediaVault Cron - Remote Command Execution (Metasploit)
CVE-2013-3632HIGHremotelinux31 Oct 2013
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RISK
open
Exploit-DBVexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
CVE-2013-3591remotephp31 Oct 2013
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RISK
open
Exploit-DBVexDay Proof
Moodle - Remote Command Execution (Metasploit)
CVE-2013-3630remotelinux31 Oct 2013
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RISK
open
Exploit-DBVexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
CVE-2013-3628remotelinux31 Oct 2013
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RISK
open
Exploit-DB
Opsview pre 4.4.1 - Blind SQL Injection
CVE-2013-5694webappsphp31 Oct 2013
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb
23RISK
open
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2311remotephp31 Oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RISK
open
Exploit-DBVexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
CVE-2013-3629remotephp31 Oct 2013
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RISK
open
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2336remotephp31 Oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RISK
open
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-1823CRITICALunder attackremotephp31 Oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
previouspage 243 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.