Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
CVE-2014-7177webappsphp28 Oct 2014
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenu Win32k Null Pointer Dereference (MS14-058) (Metasploit)
CVE-2014-4113HIGHunder attacklocalwindows28 Oct 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISK
open
Exploit-DBVexDay Proof
Enalean Tuleap 7.4.99.5 - Blind SQL Injection
CVE-2014-7176webappsphp28 Oct 2014
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
CVE-2014-7176webappsphp28 Oct 2014
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Centreon - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828remoteunix27 Oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISK
open
Exploit-DBVexDay Proof
Binary File Descriptor Library (libbfd) - Out-of-Bounds Crash
CVE-2014-6277doslinux27 Oct 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
35RISK
open
Exploit-DBVexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
CVE-2014-2647webappsmultiple27 Oct 2014
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
CVE-2014-7228remotephp21 Oct 2014
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RISK
open
Exploit-DBVexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
CVE-2014-4872remotewindows21 Oct 2014
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISK
open
Exploit-DBVexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
CVE-2011-1485locallinux20 Oct 2014
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-4114HIGHunder attacklocalwindows_x8620 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-6352HIGHunder attacklocalwindows_x8620 Oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
Exploit-DBVexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
CVE-2014-0995doswindows17 Oct 2014
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
28RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
CVE-2014-3704webappsphp17 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
CVE-2014-3704webappsphp17 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
CVE-2014-3704webappsphp16 Oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828webappslinux15 Oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RISK
open
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3829webappslinux15 Oct 2014
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RISK
open
Exploit-DBVexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
CVE-2014-4971localwindows_x8615 Oct 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISK
open
Exploit-DBVexDay Proof
YourMembers Plugin - Blind SQL Injection
CVE-2014-100003webappsphp14 Oct 2014
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISK
open
Exploit-DBVexDay Proof
F5 iControl - Remote Command Execution (Metasploit)
CVE-2014-2928remoteunix09 Oct 2014
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5
50RISK
open
Exploit-DBVexDay Proof
Nessus Web UI 2.3.3 - Persistent Cross-Site Scripting
CVE-2014-7280webappsmultiple09 Oct 2014
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s
23RISK
open
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) - Remote Command Execution (Metasploit)
CVE-2014-6287CRITICALunder attackremotewindows09 Oct 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
Exploit-DBVexDay Proof
WordPress Plugin InfusionSoft - Arbitrary File Upload (Metasploit)
CVE-2014-6446remotephp09 Oct 2014
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RISK
open
Exploit-DBVexDay Proof
Asx to Mp3 2.7.5 - Local Stack Overflow
CVE-2009-1324localwindows07 Oct 2014
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-3671remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-7910webappscgi06 Oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-62771webappscgi06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-3659remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-6271CRITICALunder attackremotelinux06 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.