Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
24,443 exploits
Exploit-DBVexDay Proof
WordPress Plugin Duplicator - Cross-Site Scripting
CVE-2013-4625webappsphp24 Jul 2013
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr
43RISK
open
Exploit-DBVexDay Proof
FOSCAM IP-Cameras - Improper Access Restrictions
CVE-2013-2574webappshardware24 Jul 2013
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
28RISK
open
Exploit-DBVexDay Proof
Magnolia CMS - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4759webappsphp24 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 fo
23RISK
open
Exploit-DB
Samsung PS50C7700 TV - Denial of Service
CVE-2013-4890doshardware23 Jul 2013
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon cras
23RISK
open
Exploit-DBVexDay Proof
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)
CVE-2013-2121remotelinux23 Jul 2013
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RISK
open
Exploit-DBVexDay Proof
Artweaver 3.1.5 - '.awd' Buffer Overflow
CVE-2013-2576doswindows23 Jul 2013
Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISK
open
Exploit-DBVexDay Proof
XnView 2.03 - '.pct' Buffer Overflow
CVE-2013-2577doswindows23 Jul 2013
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RISK
open
Exploit-DBVexDay Proof
VMware vCenter - Chargeback Manager ImageUploadServlet Arbitrary File Upload (Metasploit)
CVE-2013-3520remotewindows23 Jul 2013
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers t
50RISK
open
Exploit-DB
Microsoft DirectShow - Arbitrary Memory Overwrite (MS13-056)
CVE-2013-3174doswindows23 Jul 2013
DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
35RISK
open
Exploit-DBVexDay Proof
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
CVE-2013-1017remotewindows22 Jul 2013
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RISK
open
Exploit-DBVexDay Proof
HP Managed Printing Administration - jobAcct Remote Command Execution (Metasploit)
CVE-2011-4166remotewindows22 Jul 2013
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.0.7 - Remote (Metasploit)
CVE-2013-4730remotewindows22 Jul 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
Anchor CMS 0.9.1 - Persistent Cross-Site Scripting
CVE-2013-5099webappsphp18 Jul 2013
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote at
23RISK
open
Exploit-DB
Symantec Workspace Virtualization 6.4.1895.0 - Kernel Mode Privilege Escalation
CVE-2013-4679localwindows18 Jul 2013
Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows l
23RISK
open
Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
CVE-2013-4858doswindows18 Jul 2013
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (applica
28RISK
open
Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
CVE-2014-2671doswindows18 Jul 2013
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RISK
open
Exploit-DB
Xibo 1.2.2/1.4.1 - 'index.php?p' Directory Traversal
CVE-2013-5979webappsphp18 Jul 2013
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attacke
43RISK
open
Exploit-DBVexDay Proof
Squid 3.3.5 - Denial of Service (PoC)
CVE-2013-4123doslinux16 Jul 2013
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of
45RISK
open
Exploit-DBVexDay Proof
BlazeDVD Pro Player 6.1 - Direct RET Local Stack Buffer Overflow
CVE-2006-6199localwindows16 Jul 2013
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISK
open
Exploit-DB
rpcbind - CALLIT procedure UDP Crash (PoC)
CVE-2013-1950doslinux16 Jul 2013
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind
23RISK
open
Exploit-DBVexDay Proof
Apache Struts 2.2.3 - Multiple Open Redirections
CVE-2013-2248remotemultiple16 Jul 2013
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to
60RISK
open
Exploit-DBVexDay Proof
ReadyMedia - Remote Heap Buffer Overflow
CVE-2013-2739remotewindows15 Jul 2013
MiniDLNA has heap-based buffer overflow
23RISK
open
Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
CVE-2013-4945webappsasp13 Jul 2013
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-0742localwindows13 Jul 2013
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial
35RISK
open
Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
CVE-2013-4883webappswindows13 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extens
23RISK
open
Exploit-DB
Tri-PLC Nano-10 r81 - Denial of Service
CVE-2013-2784doshardware13 Jul 2013
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bo
23RISK
open
Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
CVE-2013-4946webappsasp13 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers t
23RISK
open
Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
CVE-2013-4882webappswindows13 Jul 2013
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (e
23RISK
open
Exploit-DBVexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-3248localwindows13 Jul 2013
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wi
43RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Pie Register - 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4954webappsphp12 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before
23RISK
open
previouspage 252 / 815next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.