Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,207cataloged exploits
36,419CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0333remotemultiple29 Jan 2013
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISK
open
Exploit-DBVexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-7387webappsphp28 Jan 2013
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RISK
open
Exploit-DBVexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-1412webappsphp28 Jan 2013
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RISK
open
Exploit-DBVexDay Proof
Novell eDirectory 8 - Remote Buffer Overflow (Metasploit)
CVE-2012-0432remotemultiple24 Jan 2013
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RISK
open
Exploit-DBVexDay Proof
WordPress Plugin WP-Table Reloaded - 'id' Cross-Site Scripting
CVE-2013-1463webappsphp24 Jan 2013
Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4
23RISK
open
Exploit-DBVexDay Proof
Java Applet - AverageRangeStatisticImpl Remote Code Execution (Metasploit)
CVE-2012-5076CRITICALunder attackremotejava24 Jan 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RISK
open
Exploit-DBVexDay Proof
Java Applet - Method Handle Remote Code Execution (Metasploit)
CVE-2012-5088remotemultiple24 Jan 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RISK
open
Exploit-DBVexDay Proof
ZoneMinder Video Server - packageControl Command Execution (Metasploit)
CVE-2013-0332remoteunix24 Jan 2013
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary
28RISK
open
Exploit-DBVexDay Proof
SonicWALL Gms 6 - Arbitrary File Upload (Metasploit)
CVE-2013-1359remotemultiple24 Jan 2013
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RISK
open
Exploit-DBVexDay Proof
ZoneMinder Video Server - packageControl Command Execution (Metasploit)
CVE-2013-0232remoteunix24 Jan 2013
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitra
50RISK
open
Exploit-DBVexDay Proof
gpEasy CMS - 'section' Cross-Site Scripting
CVE-2013-0807webappsphp23 Jan 2013
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS
23RISK
open
Exploit-DBVexDay Proof
Perforce P4Web - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-1410webappsjsp22 Jan 2013
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
23RISK
open
Exploit-DBVexDay Proof
DigiLIBE - Execution-After-Redirect Information Disclosure
CVE-2013-1402webappsphp22 Jan 2013
DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sen
23RISK
open
Exploit-DBVexDay Proof
F5 Networks BIG-IP - XML External Entity Injection
CVE-2012-2997remotehardware21 Jan 2013
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 1
23RISK
open
Exploit-DBVexDay Proof
GNU Coreutils 'sort' Text Utility - Local Buffer Overflow
CVE-2013-0221locallinux21 Jan 2013
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segment
23RISK
open
Exploit-DBVexDay Proof
Apache OFBiz 10.4.x - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-0177remotemultiple18 Jan 2013
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business
28RISK
open
Exploit-DBVexDay Proof
Oracle Application Framework - Diagnostic Mode Bypass
CVE-2013-0397webappsjsp16 Jan 2013
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, a
23RISK
open
Exploit-DBVexDay Proof
Nagios3 - 'history.cgi' Host Command Execution (Metasploit)
CVE-2012-6096remotelinux16 Jan 2013
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RISK
open
Exploit-DBVexDay Proof
freeSSHd 1.2.6 - Authentication Bypass (Metasploit)
CVE-2012-6066remotewindows15 Jan 2013
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RISK
open
Exploit-DBVexDay Proof
phpShop 2.0 - SQL Injection
CVE-2009-4571webappsphp14 Jan 2013
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
phpShop 2.0 - SQL Injection
CVE-2008-0681webappsphp14 Jan 2013
SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect
CVE-2013-4266webappsphp13 Jan 2013
20RISK
open
Exploit-DBVexDay Proof
phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect
CVE-2013-5123webappsphp13 Jan 2013
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh
23RISK
open
Exploit-DBVexDay Proof
Nagios3 - 'history.cgi' Remote Command Execution
CVE-2012-6096remotemultiple13 Jan 2013
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RISK
open
Exploit-DBVexDay Proof
Java Applet JMX - Remote Code Execution (Metasploit) (1)
CVE-2013-0422CRITICALunder attackransomwareremotejava11 Jan 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP Bypass) (MS12-037)
CVE-2012-1876remotewindows10 Jan 2013
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISK
open
Exploit-DBVexDay Proof
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0156remotemultiple10 Jan 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Option Element Use-After-Free (MS11-081) (Metasploit)
CVE-2011-1996remotewindows10 Jan 2013
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RISK
open
Exploit-DBVexDay Proof
Dell OpenManage Server Administrator - Cross-Site Scripting
CVE-2012-6272remotemultiple09 Jan 2013
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.
23RISK
open
Exploit-DBVexDay Proof
Quick.CMS / Quick.Cart - Cross-Site Scripting
CVE-2012-6430webappsphp09 Jan 2013
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor
23RISK
open
previouspage 112 / 824next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.