Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,557cataloged exploits
37,313CVEs with public exploitation
24,695lab-tested
24,478 exploits
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3612webappshardware18 Nov 2013
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which
28RISK
open
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
CVE-2013-6937localwindows14 Nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
23RISK
open
Exploit-DBVexDay Proof
Symantec Altiris DS - SQL Injection (Metasploit)
CVE-2008-2286remotewindows13 Nov 2013
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allow
50RISK
open
Exploit-DBVexDay Proof
Testa OTMS - Multiple SQL Injections
CVE-2013-6873webappsphp13 Nov 2013
SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb
23RISK
open
Exploit-DB
TOSHIBA e-Studio 232/233/282/283 - Cross-Site Request Forgery (Change Admin Password)
CVE-2014-1990webappshardware13 Nov 2013
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Stu
23RISK
open
Exploit-DB
Juniper Junos J-Web - Privilege Escalation
CVE-2013-6618webappsphp12 Nov 2013
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,
28RISK
open
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' File Local Buffer Overflow (SEH Unicode)
CVE-2013-7409localwindows12 Nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5218webappshardware08 Nov 2013
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5220webappshardware08 Nov 2013
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device
23RISK
open
Exploit-DBVexDay Proof
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)
CVE-2013-6364webappsphp08 Nov 2013
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4468remotelinux08 Nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5219webappshardware08 Nov 2013
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrar
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5039webappshardware08 Nov 2013
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.1
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5038webappshardware08 Nov 2013
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a
23RISK
open
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-3528webappsphp08 Nov 2013
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack
23RISK
open
Exploit-DB
Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection
CVE-2013-6164webappsphp08 Nov 2013
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-7382remotelinux08 Nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RISK
open
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5037webappshardware08 Nov 2013
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers
23RISK
open
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4467remotelinux08 Nov 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RISK
open
Exploit-DB
appRain 3.0.2 - Blind SQL Injection
CVE-2013-6058webappsphp08 Nov 2013
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-2749webappsphp08 Nov 2013
20RISK
open
Exploit-DBVexDay Proof
Vivotek IP Cameras - RTSP Authentication Bypass
CVE-2013-4985webappshardware08 Nov 2013
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RISK
open
Exploit-DBVexDay Proof
Hanso Player 2.5.0 - 'm3u' Buffer Overflow (Denial of Service)
CVE-2013-7280doswindows05 Nov 2013
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RISK
open
Exploit-DB
Apache Tomcat 5.5.25 - Cross-Site Request Forgery
CVE-2013-6357webappsmultiple04 Nov 2013
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows re
23RISK
open
Exploit-DBVexDay Proof
Google Android - Signature Verification Security Bypass
CVE-2013-6792remoteandroid04 Nov 2013
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
23RISK
open
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - Local Buffer Overflow (SEH)
CVE-2013-6935localwindows01 Nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RISK
open
Exploit-DBVexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
CVE-2013-3591remotephp31 Oct 2013
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RISK
open
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2311remotephp31 Oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RISK
open
Exploit-DBVexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
CVE-2013-3628remotelinux31 Oct 2013
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RISK
open
Exploit-DBVexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
CVE-2013-3629remotephp31 Oct 2013
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RISK
open
previouspage 244 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.