Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
QNX 6.4.x/6.5.x ifwatchd - Local Privilege Escalation
CVE-2014-2533localqnx10 Mar 2014
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RISK
open
Exploit-DBVexDay Proof
GetGo Download Manager 4.9.0.1982 - HTTP Response Header Buffer Overflow Remote Code Execution
CVE-2014-2206remotewindows09 Mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple06 Mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0114remotemultiple06 Mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple06 Mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISK
open
Exploit-DBVexDay Proof
ALLPlayer - '.m3u' Local Buffer Overflow (Metasploit)
CVE-2013-7409localwindows05 Mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10035webappsphp03 Mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RISK
open
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10034webappsphp03 Mar 2014
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RISK
open
Exploit-DBVexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
CVE-2013-7409localwindows03 Mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
CVE-2013-5877webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
CVE-2014-0372webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
CVE-2014-0379webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
CVE-2013-5795webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISK
open
Exploit-DBVexDay Proof
VCDGear 3.50 - '.cue' Local Stack Buffer Overflow
CVE-2007-2568localwindows28 Feb 2014
Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
CVE-2014-0750remotewindows28 Feb 2014
GE Proficy HMI/SCADA Path Traversal
78RISK
open
Exploit-DBVexDay Proof
POSH 3.1.x - 'addtoapplication.php' SQL Injection
CVE-2014-2211webappsphp26 Feb 2014
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5015remotewindows26 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5014remotewindows26 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
Sendy 1.1.8.4 - SQL Injection
CVE-2014-100012webappsphp25 Feb 2014
SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5015remotewindows23 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5014remotewindows23 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (2)
CVE-2013-5019remotewindows22 Feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open
Exploit-DBVexDay Proof
SolidWorks Workgroup PDM 2014 SP2 - Arbitrary File Write
CVE-2014-100015remotewindows22 Feb 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection
CVE-2014-1854webappsphp22 Feb 2014
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p
23RISK
open
Exploit-DBVexDay Proof
ATutor - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
CVE-2014-2091webappsphp22 Feb 2014
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote auth
23RISK
open
Exploit-DBVexDay Proof
eshtery CMS - 'FileManager.aspx' Local File Disclosure
CVE-2014-2069webappsasp22 Feb 2014
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname
28RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - Remote Buffer Overflow
CVE-2013-4730remotewindows20 Feb 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
MediaWiki - 'Thumb.php' Remote Command Execution (Metasploit)
CVE-2014-1610remotemultiple19 Feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RISK
open
Exploit-DBVexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
CVE-2014-2072remotemultiple19 Feb 2014
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RISK
open
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
CVE-2013-5019remotewindows18 Feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.