Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALunder attackremotewindows18 Feb 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 Feb 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RISK
open
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 Feb 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 Feb 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RISK
open
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 Feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISK
open
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 Feb 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RISK
open
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 Feb 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 Feb 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RISK
open
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 Feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 Feb 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RISK
open
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 Feb 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISK
open
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 Feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Exploit-DBVexDay Proof
ImpressCMS 1.3.5 - Multiple Vulnerabilities
CVE-2014-1836webappsphp05 Feb 2014
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows
23RISK
open
Exploit-DBVexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
CVE-2008-1461remotewindows05 Feb 2014
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple05 Feb 2014
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Exploit-DBVexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
CVE-2014-1683remotelinux05 Feb 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RISK
open
Exploit-DBVexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
CVE-2012-0394remotejava05 Feb 2014
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISK
open
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
CVE-2013-7183doscgi03 Feb 2014
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RISK
open
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
CVE-2013-7179remotecgi03 Feb 2014
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
CVE-2014-0038locallinux_x86-6402 Feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
CVE-2014-0038locallinux02 Feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISK
open
Exploit-DBVexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
CVE-2014-1610webappsmultiple01 Feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
CVE-2013-4730remotewindows29 Jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'ABOR' Remote Buffer Overflow
CVE-2013-4730remotewindows29 Jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1632webappsphp28 Jan 2014
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RISK
open
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1631webappsphp28 Jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISK
open
Exploit-DBVexDay Proof
Eventum - Insecure File Permissions
CVE-2014-1631webappsphp27 Jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISK
open
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Buffer Overflow
CVE-2006-2465doslinux27 Jan 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RISK
open
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 Jan 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RISK
open
Exploit-DBVexDay Proof
Daum Game 1.1.0.5 - ActiveX 'IconCreate Method' Remote Stack Buffer Overflow
CVE-2013-7246remotewindows24 Jan 2014
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.