Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
WordPress Plugin GigPress 2.3.8 - SQL Injection
CVE-2015-4066webappsphp26 May 2015
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISK
open
Exploit-DBVexDay Proof
Sendio ESP - Information Disclosure
CVE-2014-0999webappsjsp26 May 2015
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RISK
open
Exploit-DBVexDay Proof
Fuse 2.9.3-15 - Local Privilege Escalation
CVE-2015-3202locallinux23 May 2015
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISK
open
Exploit-DBVexDay Proof
Phoenix Contact ILC 150 ETH PLC - Remote Control Script
CVE-2014-9195remotehardware20 May 2015
Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
85RISK
open
Exploit-DBVexDay Proof
WordPress Plugin FeedWordPress 2015.0426 - SQL Injection
CVE-2015-4018webappsphp20 May 2015
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 8.0/8.1 (x64) - 'TrackPopupMenu' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHunder attacklocalwindows_x86-6419 May 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1679localwindows18 May 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1701HIGHunder attackransomwarelocalwindows18 May 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1678localwindows18 May 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1680localwindows18 May 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1676localwindows18 May 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1677localwindows18 May 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RISK
open
Exploit-DBVexDay Proof
Novell ZENworks Configuration Management - Arbitrary File Upload (Metasploit)
CVE-2015-0779remotejava08 May 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin RevSlider 3.0.95 - Arbitrary File Upload / Execution (Metasploit)
CVE-2014-9735remotephp08 May 2015
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - NetConnection Type Confusion (Metasploit)
CVE-2015-0336remotewindows08 May 2015
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - domainMemory ByteArray Use-After-Free (Metasploit)
CVE-2015-0359remotewindows08 May 2015
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - UncompressViaZlibVariant Uninitialized Memory (Metasploit)
CVE-2014-8440remotewindows01 May 2015
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RISK
open
Exploit-DBVexDay Proof
WordPress Core 4.2 - Persistent Cross-Site Scripting
CVE-2015-3440webappsphp27 Apr 2015
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i
28RISK
open
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 2.8 (Windows 7) - '.wav' File Buffer Overflow (SEH) (DEP Bypass)
CVE-2011-5165localwindows24 Apr 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 2.8 - '.wav' File Buffer Overflow (SEH)
CVE-2011-5165localwindows23 Apr 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - copyPixelsToByteArray Integer Overflow (Metasploit)
CVE-2014-0556remotewindows21 Apr 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RISK
open
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2843webappsphp21 Apr 2015
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Creative Contact Form - Arbitrary File Upload (Metasploit)
CVE-2014-8739remotephp21 Apr 2015
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2842webappsphp21 Apr 2015
Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAu
28RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Reflex Gallery - Arbitrary File Upload (Metasploit)
CVE-2015-4133remotephp21 Apr 2015
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISK
open
Exploit-DBVexDay Proof
BlueDragon CFChart Servlet 7.1.1.17759 - Arbitrary File Retrieval/Deletion
CVE-2014-5370webappscfm21 Apr 2015
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDra
23RISK
open
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2844webappsphp21 Apr 2015
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arb
28RISK
open
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2845webappsphp21 Apr 2015
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RISK
open
Exploit-DBVexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
CVE-2015-1318locallinux14 Apr 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RISK
open
Exploit-DBVexDay Proof
Abrt (Fedora 21) - Race Condition
CVE-2015-3315locallinux14 Apr 2015
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.