Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
HP Insight Diagnostics - Remote Code Injection
CVE-2013-3574webappsphp10 Jun 2013
Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.
23RISK
open
Exploit-DBVexDay Proof
HP Insight Diagnostics 9.4.0.4710 - Local File Inclusion
CVE-2013-3575webappsphp10 Jun 2013
hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or requi
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - textNode Use-After-Free (MS13-037) (Metasploit)
CVE-2013-1311remotewindows07 Jun 2013
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a cr
28RISK
open
Exploit-DBVexDay Proof
Quick TFTP Server Pro 2.2 - Denial of Service
CVE-2008-1610doswindows07 Jun 2013
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.3.5 - 'b43' Wireless Driver Privilege Escalation
CVE-2013-2852locallinux07 Jun 2013
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43
23RISK
open
Exploit-DBVexDay Proof
Novell ZENworks Mobile Device Managment 2.6.1/2.7.0 - Local File Inclusion (Metasploit)
CVE-2013-1081webappswindows07 Jun 2013
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RISK
open
Exploit-DBVexDay Proof
Xpient - Cash Drawer Operation
CVE-2013-2571remotehardware05 Jun 2013
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary
28RISK
open
Exploit-DBVexDay Proof
Apache Struts - includeParams Remote Code Execution (Metasploit)
CVE-2013-2115remotemultiple05 Jun 2013
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RISK
open
Exploit-DBVexDay Proof
Plesk < 9.5.4 - Remote Command Execution
CVE-2013-4878remotephp05 Jun 2013
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has a
35RISK
open
Exploit-DBVexDay Proof
MiniUPnPd 1.0 - Remote Stack Buffer Overflow Remote Code Execution (Metasploit)
CVE-2013-0230remotelinux05 Jun 2013
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RISK
open
Exploit-DBVexDay Proof
Apache Struts - OGNL Expression Injection
CVE-2013-2134remotemultiple05 Jun 2013
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted acti
45RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX Server - DirectoryService Buffer Overflow
CVE-2013-0984dososx05 Jun 2013
Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial o
28RISK
open
Exploit-DBVexDay Proof
Oracle WebCenter Content - 'CheckOutAndOpen.dll' ActiveX Remote Code Execution (Metasploit)
CVE-2013-1559remotewindows05 Jun 2013
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.
50RISK
open
Exploit-DBVexDay Proof
Apache Struts - includeParams Remote Code Execution (Metasploit)
CVE-2013-1966remotemultiple05 Jun 2013
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RISK
open
Exploit-DBVexDay Proof
QNAP VioStor NVR / QNAP NAS - Remote Code Execution
CVE-2013-0143webappscgi05 Jun 2013
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in Q
23RISK
open
Exploit-DBVexDay Proof
Telaen 2.7.x - Cross-Site Scripting
CVE-2013-2623webappsphp04 Jun 2013
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the
23RISK
open
Exploit-DBVexDay Proof
Telaen 2.7.x - Open Redirection
CVE-2013-2621webappsphp04 Jun 2013
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim
43RISK
open
Exploit-DBVexDay Proof
MongoDB - 'conn' Mongo Object Remote Code Execution
CVE-2013-3969remotemultiple04 Jun 2013
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
CVE-2013-3661localwindows03 Jun 2013
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
CVE-2013-3660HIGHunder attacklocalwindows03 Jun 2013
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RISK
open
Exploit-DBVexDay Proof
Telaen - Information Disclosure
CVE-2013-2624webappsphp03 Jun 2013
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
CVE-2013-3130localwindows03 Jun 2013
20RISK
open
Exploit-DBVexDay Proof
Lianja SQL 1.0.0RC5.1 - db_netserver Stack Buffer Overflow (Metasploit)
CVE-2013-3563remotewindows31 May 2013
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a de
50RISK
open
Exploit-DBVexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
CVE-2013-2570webappshardware29 May 2013
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to t
28RISK
open
Exploit-DBVexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
CVE-2013-2568webappshardware29 May 2013
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless
35RISK
open
Exploit-DBVexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
CVE-2013-2569webappshardware29 May 2013
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is dis
35RISK
open
Exploit-DBVexDay Proof
IBM SPSS SamplePower C1Tab - ActiveX Heap Overflow (Metasploit)
CVE-2012-5946remotewindows29 May 2013
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac
50RISK
open
Exploit-DBVexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
CVE-2013-2572webappshardware29 May 2013
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 d
28RISK
open
Exploit-DBVexDay Proof
MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
CVE-2013-1604webappshardware29 May 2013
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
CVE-2013-2573webappshardware29 May 2013
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cam
35RISK
open
previouspage 105 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.