Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
WordPress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal
CVE-2014-8801webappsphp19 Nov 2014
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress
28RISK
open
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (2)
CVE-2014-7146remotephp18 Nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RISK
open
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-7146webappsmultiple18 Nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RISK
open
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-8598webappsmultiple18 Nov 2014
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.1 Bypass) (MS12-037)
CVE-2012-1876remotewindows17 Nov 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
OSSEC 2.8 - 'hosts.deny' Local Privilege Escalation
CVE-2014-5284locallinux14 Nov 2014
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows14 Nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
CVE-2014-8997webappsphp13 Nov 2014
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
CVE-2014-6332HIGHunder attackremotewindows13 Nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9004webappsphp10 Nov 2014
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9005webappsphp10 Nov 2014
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Visual Mining NetCharts Server - Remote Code Execution (Metasploit)
CVE-2014-8516remotejava10 Nov 2014
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co
60RISK
open
Exploit-DBVexDay Proof
phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2014-8954webappsphp10 Nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
Citrix Netscaler SOAP Handler - Remote Code Execution (Metasploit)
CVE-2014-7140remotebsd06 Nov 2014
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetS
28RISK
open
Exploit-DBVexDay Proof
Belkin N750 - 'jump?login' Remote Buffer Overflow
CVE-2014-1635remotehardware06 Nov 2014
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISK
open
Exploit-DBVexDay Proof
X7 Chat 2.0.5 - 'message.php' PHP Code Execution (Metasploit)
CVE-2014-8998remotephp06 Nov 2014
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
CVE-2014-3704webappsphp03 Nov 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotelinux29 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotelinux29 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotelinux29 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotelinux29 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotelinux29 Oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotelinux29 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotelinux29 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotelinux29 Oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DBVexDay Proof
MAARCH 1.4 - Arbitrary File Upload
CVE-2015-1587webappsphp29 Oct 2014
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RISK
open
Exploit-DBVexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
CVE-2014-7176webappsphp28 Oct 2014
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.