Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Oracle Hyperion 11 - Directory Traversal
CVE-2013-3803webappswindows02 Aug 2013
Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.
23RISK
open
Exploit-DBVexDay Proof
HP Data Protector - CMD Install Service (Metasploit)
CVE-2011-0922remotewindows02 Aug 2013
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RISK
open
Exploit-DBVexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
CVE-2013-2581webappshardware02 Aug 2013
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - HWND_BROADCAST Low to Medium Integrity Privilege Escalation (MS13-005) (Metasploit)
CVE-2013-0008localwindows02 Aug 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RISK
open
Exploit-DBVexDay Proof
Ginkgo CMS - 'index.php?rang' SQL Injection
CVE-2013-5318webappsphp02 Aug 2013
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang par
23RISK
open
Exploit-DBVexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
CVE-2013-2579webappshardware02 Aug 2013
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.1
23RISK
open
Exploit-DBVexDay Proof
Cotonti 0.9.13 - SQL Injection
CVE-2013-4789webappsphp02 Aug 2013
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Karotz Smart Rabbit 12.07.19.00 - Multiple Vulnerabilities
CVE-2013-4867localhardware02 Aug 2013
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
23RISK
open
Exploit-DBVexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
CVE-2013-4863webappshardware02 Aug 2013
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISK
open
Exploit-DBVexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
CVE-2013-4865webappshardware02 Aug 2013
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open
Exploit-DBVexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
CVE-2013-4864webappshardware02 Aug 2013
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RISK
open
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'PASS' Remote Buffer Overflow
CVE-2013-4730remotewindows02 Aug 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RISK
open
Exploit-DBVexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
CVE-2013-2578webappshardware02 Aug 2013
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
60RISK
open
Exploit-DBVexDay Proof
INSTEON Hub 2242-222 - Lack of Web and API Authentication
CVE-2013-4859webappshardware02 Aug 2013
INSTEON Hub 2242-222 lacks Web and API authentication
23RISK
open
Exploit-DBVexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
CVE-2013-4861webappshardware02 Aug 2013
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote
23RISK
open
Exploit-DBVexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
CVE-2013-2580webappshardware02 Aug 2013
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-
23RISK
open
Exploit-DBVexDay Proof
SilverStripe CMS - 'MemberLoginForm.php' Information Disclosure
CVE-2013-2653webappsphp01 Aug 2013
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote
23RISK
open
Exploit-DBVexDay Proof
Plone - 'in_portal.py' < 4.1.3 Session Hijacking
CVE-2013-4200webappspython31 Jul 2013
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x t
23RISK
open
Exploit-DBVexDay Proof
Jahia xCM - '/engines/manager.jsp?site' Cross-Site Scripting
CVE-2013-4624webappsphp31 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
Jahia xCM - '/administration/' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4624webappsphp31 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
Novell Client 2 SP3 - 'nicm.sys 3.1.11.0' Local Privilege Escalation
CVE-2013-3956localwindows29 Jul 2013
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RISK
open
Exploit-DBVexDay Proof
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
CVE-2013-2251CRITICALunder attackremotemultiple27 Jul 2013
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open
Exploit-DBVexDay Proof
Symantec Web Gateway 5.1.0.x - Multiple Vulnerabilities
CVE-2013-1616webappsphp27 Jul 2013
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbit
28RISK
open
Exploit-DBVexDay Proof
xmonad XMonad.Hooks.DynamicLog Module - Multiple Remote Command Injection Vulnerabilities
CVE-2013-1436remotelinux26 Jul 2013
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands
23RISK
open
Exploit-DBVexDay Proof
Magnolia CMS - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4759webappsphp24 Jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 fo
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Duplicator - Cross-Site Scripting
CVE-2013-4625webappsphp24 Jul 2013
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr
43RISK
open
Exploit-DBVexDay Proof
FOSCAM IP-Cameras - Improper Access Restrictions
CVE-2013-2574webappshardware24 Jul 2013
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
28RISK
open
Exploit-DBVexDay Proof
Artweaver 3.1.5 - '.awd' Buffer Overflow
CVE-2013-2576doswindows23 Jul 2013
Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISK
open
Exploit-DBVexDay Proof
XnView 2.03 - '.pct' Buffer Overflow
CVE-2013-2577doswindows23 Jul 2013
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RISK
open
Exploit-DBVexDay Proof
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)
CVE-2013-2121remotelinux23 Jul 2013
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RISK
open
previouspage 102 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.