Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,106cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'license.php' Remote Command Execution (Metasploit)
CVE-2012-0261webappsmultiple25 Jan 2015
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISK
open
Exploit-DBVexDay Proof
ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2014-5301remotejava20 Jan 2015
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape
CVE-2014-4492localosx20 Jan 2015
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows < 8.1 (x86/x64) - User Profile Service Privilege Escalation (MS15-003)
CVE-2015-0004localwindows18 Jan 2015
The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2
23RISK
open
Exploit-DBVexDay Proof
Lexmark MarkVision Enterprise - Arbitrary File Upload (Metasploit)
CVE-2014-8741remotejava13 Jan 2015
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RISK
open
Exploit-DBVexDay Proof
Oracle MySQL (Windows) - FILE Privilege Abuse (Metasploit)
CVE-2012-5613remotewindows13 Jan 2015
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload (Metasploit)
CVE-2014-10021remotephp13 Jan 2015
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RISK
open
Exploit-DBVexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
CVE-2010-4279remotephp08 Jan 2015
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISK
open
Exploit-DBVexDay Proof
BulletProof FTP Client - BPS Buffer Overflow (Metasploit)
CVE-2014-2973localwindows06 Jan 2015
35RISK
open
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'welcome' Remote Command Execution (Metasploit)
CVE-2012-0262webappsmultiple05 Jan 2015
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RISK
open
Exploit-DBVexDay Proof
ASUSWRT 3.0.0.4.376_1071 - LAN Backdoor Command Execution
CVE-2014-9583remotehardware04 Jan 2015
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISK
open
Exploit-DBVexDay Proof
e107 2 Bootstrap CMS - Cross-Site Scripting
CVE-2015-1057webappsphp03 Jan 2015
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation
CVE-2015-0002localwindows01 Jan 2015
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RISK
open
Exploit-DBVexDay Proof
ProjectSend - Arbitrary File Upload (Metasploit)
CVE-2014-9567remotephp31 Dec 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RISK
open
Exploit-DBVexDay Proof
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
CVE-2014-9516webappsphp31 Dec 2014
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Notepad++ 6.6.9 - Buffer Overflow
CVE-2014-1004doswindows22 Dec 2014
20RISK
open
Exploit-DBVexDay Proof
Notepad++ 6.6.9 - Buffer Overflow
CVE-2014-9456doswindows22 Dec 2014
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISK
open
Exploit-DBVexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
CVE-2013-0757remotemultiple18 Dec 2014
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RISK
open
Exploit-DBVexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
CVE-2013-0758remotemultiple18 Dec 2014
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RISK
open
Exploit-DBVexDay Proof
Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Code Execution (Metasploit)
CVE-2014-4936localwindows16 Dec 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RISK
open
Exploit-DBVexDay Proof
Tuleap - PHP Unserialize Code Execution (Metasploit)
CVE-2014-8791remotephp15 Dec 2014
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RISK
open
Exploit-DBVexDay Proof
OpenEMR 4.1.2(7) - Multiple SQL Injections
CVE-2014-5462webappsphp10 Dec 2014
Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Privilege Escalation (MS14-068)
CVE-2014-6324HIGHunder attackremotewindows05 Dec 2014
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RISK
open
Exploit-DBVexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
CVE-2013-1428remotemultiple02 Dec 2014
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
CVE-2014-4404HIGHunder attacklocalosx02 Dec 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RISK
open
Exploit-DBVexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
CVE-2014-9119webappsphp26 Nov 2014
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RISK
open
Exploit-DBVexDay Proof
Advantech EKI-6340 - Command Injection
CVE-2014-8387webappscgi24 Nov 2014
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RISK
open
Exploit-DBVexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
CVE-2014-4880remotelinux24 Nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
CVE-2014-9178webappsphp21 Nov 2014
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
CVE-2014-6332HIGHunder attackremotewindows20 Nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.