Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
ownCloud 4.0.x/4.5.x - 'upload.php?Filename' Remote Code Execution
CVE-2014-2044webappsmultiple10 Mar 2014
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RISK
open
Exploit-DBVexDay Proof
GetGo Download Manager 4.9.0.1982 - HTTP Response Header Buffer Overflow Remote Code Execution
CVE-2014-2206remotewindows09 Mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple06 Mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple06 Mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0114remotemultiple06 Mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISK
open
Exploit-DBVexDay Proof
ALLPlayer - '.m3u' Local Buffer Overflow (Metasploit)
CVE-2013-7409localwindows05 Mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DBVexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
CVE-2013-7409localwindows03 Mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10035webappsphp03 Mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RISK
open
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10034webappsphp03 Mar 2014
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
CVE-2013-5795webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
CVE-2013-5877webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
CVE-2014-0372webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
CVE-2014-0379webappswindows01 Mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
Exploit-DBVexDay Proof
VCDGear 3.50 - '.cue' Local Stack Buffer Overflow
CVE-2007-2568localwindows28 Feb 2014
Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
CVE-2014-0750remotewindows28 Feb 2014
GE Proficy HMI/SCADA Path Traversal
78RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5015remotewindows26 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
CVE-2013-5014remotewindows26 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
POSH 3.1.x - 'addtoapplication.php' SQL Injection
CVE-2014-2211webappsphp26 Feb 2014
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows
23RISK
open
Exploit-DBVexDay Proof
Sendy 1.1.8.4 - SQL Injection
CVE-2014-100012webappsphp25 Feb 2014
SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5014remotewindows23 Feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RISK
open
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
CVE-2013-5015remotewindows23 Feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RISK
open
Exploit-DBVexDay Proof
WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection
CVE-2014-1854webappsphp22 Feb 2014
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p
23RISK
open
Exploit-DBVexDay Proof
SolidWorks Workgroup PDM 2014 SP2 - Arbitrary File Write
CVE-2014-100015remotewindows22 Feb 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RISK
open
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (2)
CVE-2013-5019remotewindows22 Feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RISK
open
Exploit-DBVexDay Proof
ATutor - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
CVE-2014-2091webappsphp22 Feb 2014
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote auth
23RISK
open
Exploit-DBVexDay Proof
eshtery CMS - 'FileManager.aspx' Local File Disclosure
CVE-2014-2069webappsasp22 Feb 2014
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname
28RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - Remote Buffer Overflow
CVE-2013-4730remotewindows20 Feb 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
MediaWiki - 'Thumb.php' Remote Command Execution (Metasploit)
CVE-2014-1610remotemultiple19 Feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RISK
open
Exploit-DBVexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
CVE-2014-2072remotemultiple19 Feb 2014
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RISK
open
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALunder attackremotewindows18 Feb 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.