Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
vTiger CRM 5.4.0 SOAP - AddEmailAttachment Arbitrary File Upload (Metasploit)
CVE-2013-3214remotephp07 Jan 2014
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISK
open
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/add_topic.php' Cross-Site Request Forgery (Topic Creation)
CVE-2014-1915webappsphp07 Jan 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RISK
open
Exploit-DBVexDay Proof
Apache Libcloud Digital Ocean API - Local Information Disclosure
CVE-2013-6480locallinux01 Jan 2014
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows loca
23RISK
open
Exploit-DBVexDay Proof
CMS Afroditi - 'id' SQL Injection
CVE-2013-7278webappsasp30 Dec 2013
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory Traversal
CVE-2013-7240webappsphp30 Dec 2013
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote
43RISK
open
Exploit-DBVexDay Proof
JForum 'adminUsers' Module - Cross-Site Request Forgery
CVE-2013-7209webappsphp26 Dec 2013
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attack
23RISK
open
Exploit-DBVexDay Proof
HP SiteScope issueSiebelCmd - Remote Code Execution (Metasploit)
CVE-2013-4835remoteunix24 Dec 2013
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RISK
open
Exploit-DBVexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
CVE-2013-6877localwindows24 Dec 2013
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738
28RISK
open
Exploit-DBVexDay Proof
RedHat CloudForms Management Engine 5.1 - agent/linuxpkgs Directory Traversal (Metasploit)
CVE-2013-2068remotelinux24 Dec 2013
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re
50RISK
open
Exploit-DBVexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
CVE-2013-7260localwindows24 Dec 2013
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RISK
open
Exploit-DBVexDay Proof
Synology DiskStation Manager - SLICEUPLOAD Remote Command Execution (Metasploit)
CVE-2013-6955remoteunix24 Dec 2013
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RISK
open
Exploit-DBVexDay Proof
OpenSIS 'modname' - PHP Code Execution (Metasploit)
CVE-2013-1349remotelinux24 Dec 2013
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RISK
open
Exploit-DBVexDay Proof
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
CVE-2013-7091webappslinux24 Dec 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISK
open
Exploit-DBVexDay Proof
DenyHosts - 'regex.py' Remote Denial of Service
CVE-2013-6890doslinux19 Dec 2013
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Hancom Office - '.hml' File Processing Heap Buffer Overflow
CVE-2013-7420remotewindows19 Dec 2013
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attr
23RISK
open
Exploit-DBVexDay Proof
Leed - 'id' SQL Injection
CVE-2013-2627webappsphp18 Dec 2013
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Integer Overflow (MS13-101)
CVE-2013-5058doswindows17 Dec 2013
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.0.11 - '/wp-admin/options-discussion.php' Script Cross-Site Request Forgery
CVE-2013-7233webappsphp17 Dec 2013
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPre
23RISK
open
Exploit-DBVexDay Proof
Adobe Reader ToolButton - Use-After-Free (Metasploit)
CVE-2013-3346HIGHunder attackremotewindows17 Dec 2013
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitr
100RISK
open
Exploit-DBVexDay Proof
Nvidia (nvsvc) Display Driver Service - Local Privilege Escalation (Metasploit)
CVE-2013-0109localwindows_x86-6417 Dec 2013
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'ndproxy.sys' Local Privilege Escalation (Metasploit)
CVE-2013-5065HIGHunder attacklocalwindows17 Dec 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISK
open
Exploit-DBVexDay Proof
Ability Mail Server 2013 3.1.1 - Web UI Persistent Cross-Site Scripting
CVE-2013-6162remotewindows17 Dec 2013
Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
C2C Forward Auction Creator - '/auction/casp/Admin.asp' SQL Injection (Admin Authentication Bypass)
CVE-2013-7193webappsphp16 Dec 2013
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
Icinga - cgi/config.c process_cgivars Function Off-by-One Read Remote Denial of Service
CVE-2013-7108doscgi16 Dec 2013
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10
35RISK
open
Exploit-DBVexDay Proof
C2C Forward Auction Creator 2.0 - '/auction/asp/list.asp?pa' SQL Injection
CVE-2013-7193webappsphp16 Dec 2013
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
Gitlab 6.0 - Persistent Cross-Site Scripting
CVE-2013-7316webappsphp16 Dec 2013
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'additionalsettings.php' SQL Injection
CVE-2013-7189webappsphp15 Dec 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'fname' Local File Inclusion
CVE-2013-7190webappsphp15 Dec 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'id' Local File Inclusion
CVE-2013-7190webappsphp15 Dec 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'invno' SQL Injection
CVE-2013-7189webappsphp15 Dec 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.