Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Directory Traversal (Metasploit)
CVE-2013-6194remotewindows24 Jan 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RISK
open
Exploit-DBVexDay Proof
Daum Game 1.1.0.5 - ActiveX 'IconCreate Method' Remote Stack Buffer Overflow
CVE-2013-7246remotewindows24 Jan 2014
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows
28RISK
open
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 Jan 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RISK
open
Exploit-DBVexDay Proof
GoToMeeting for Android - Multiple Local Information Disclosure Vulnerabilities
CVE-2014-1664localandroid23 Jan 2014
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a
23RISK
open
Exploit-DBVexDay Proof
MuPDF 1.3 - 'xps_parse_color()' Stack Buffer Overflow
CVE-2014-2013localwindows20 Jan 2014
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote a
28RISK
open
Exploit-DBVexDay Proof
Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection
CVE-2013-7219webappsphp16 Jan 2014
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a
23RISK
open
Exploit-DBVexDay Proof
Oracle Supply Chain Products Suite - Remote Security
CVE-2013-5880remotemultiple14 Jan 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RISK
open
Exploit-DBVexDay Proof
Atmail Webmail Server - Email Body HTML Injection
CVE-2013-6017webappsphp14 Jan 2014
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
CVE-2013-2251CRITICALunder attackwebappsmultiple14 Jan 2014
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open
Exploit-DBVexDay Proof
SerComm Device - Remote Code Execution (Metasploit)
CVE-2014-0659remotehardware14 Jan 2014
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RISK
open
Exploit-DBVexDay Proof
Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections
CVE-2014-1671webappsphp13 Jan 2014
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot
23RISK
open
Exploit-DBVexDay Proof
DomPHP 0.83 - SQL Injection
CVE-2014-10038webappsphp13 Jan 2014
SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'products.php' Multiple SQL Injections
CVE-2014-1618webappsphp08 Jan 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'news.php?id' SQL Injection
CVE-2014-1618webappsphp08 Jan 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_grades.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/health_allergies.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_subjects.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/add_topic.php' Cross-Site Request Forgery (Topic Creation)
CVE-2014-1915webappsphp07 Jan 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/backup/backup_ray2.php' Database Backup Direct Request Information Disclosure
CVE-2014-1637webappsphp07 Jan 2014
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_relations.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/Admin_change_Password.php' Cross-Site Request Forgery (Admin Password Manipulation)
CVE-2014-1915webappsphp07 Jan 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_terms.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_media_codes_1.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_generations.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
IBM Forms Viewer - Unicode Buffer Overflow (Metasploit)
CVE-2013-5447localwindows07 Jan 2014
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RISK
open
Exploit-DBVexDay Proof
IcoFX - Local Stack Buffer Overflow (Metasploit)
CVE-2013-4988localwindows07 Jan 2014
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_titles.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
vTiger CRM 5.4.0 SOAP - AddEmailAttachment Arbitrary File Upload (Metasploit)
CVE-2013-3214remotephp07 Jan 2014
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_sgrades.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_school_years.php?id' SQL Injection
CVE-2014-1636webappsphp07 Jan 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.