Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALunder attackremotewindows18 Feb 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 Feb 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RISK
open
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 Feb 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 Feb 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RISK
open
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 Feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RISK
open
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 Feb 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RISK
open
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 Feb 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 Feb 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RISK
open
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 Feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 Feb 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RISK
open
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 Feb 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISK
open
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 Feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Exploit-DBVexDay Proof
ImpressCMS 1.3.5 - Multiple Vulnerabilities
CVE-2014-1836webappsphp05 Feb 2014
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows
23RISK
open
Exploit-DBVexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
CVE-2008-1461remotewindows05 Feb 2014
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RISK
open
Exploit-DBVexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
CVE-2014-1683remotelinux05 Feb 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RISK
open
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple05 Feb 2014
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISK
open
Exploit-DBVexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
CVE-2012-0394remotejava05 Feb 2014
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISK
open
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
CVE-2013-7179remotecgi03 Feb 2014
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
CVE-2013-7183doscgi03 Feb 2014
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
CVE-2014-0038locallinux_x86-6402 Feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
CVE-2014-0038locallinux02 Feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISK
open
Exploit-DBVexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
CVE-2014-1610webappsmultiple01 Feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'ABOR' Remote Buffer Overflow
CVE-2013-4730remotewindows29 Jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
CVE-2013-4730remotewindows29 Jan 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1632webappsphp28 Jan 2014
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RISK
open
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1631webappsphp28 Jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISK
open
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Buffer Overflow
CVE-2006-2465doslinux27 Jan 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RISK
open
Exploit-DBVexDay Proof
Eventum - Insecure File Permissions
CVE-2014-1631webappsphp27 Jan 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RISK
open
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 Jan 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RISK
open
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7247webappshardware24 Jan 2014
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.