Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-62771remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-3659webappscgi06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-3671webappscgi06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-7169CRITICALunder attackwebappscgi06 Oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-7910webappscgi06 Oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-3659remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-3671remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-7196remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-7169CRITICALunder attackremotelinux06 Oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-62771webappscgi06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
CVE-2014-7227webappscgi06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
CVE-2014-7227remotelinux06 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Apache mod_cgi - 'Shellshock' Remote Command Injection
CVE-2014-6271CRITICALunder attackremotelinux06 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
HP Network Node Manager I - PMD Buffer Overflow (Metasploit)
CVE-2014-2624remotelinux02 Oct 2014
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute ar
50RISK
open
Exploit-DBVexDay Proof
TeamSpeak Client 3.0.14 - Buffer Overflow
CVE-2014-7222doswindows02 Oct 2014
Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (a
28RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotelinux02 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Kolibri WebServer 2.0 - Remote Buffer Overflow (EMET 5.0 / EMET 4.1 Partial Bypass)
CVE-2014-5289remotewindows02 Oct 2014
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request
28RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotelinux02 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
TeamSpeak Client 3.0.14 - Buffer Overflow
CVE-2014-7221doswindows02 Oct 2014
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and
28RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotelinux02 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotelinux02 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
PHPCompta/NOALYSS 6.7.1 5638 - Remote Command Execution
CVE-2014-6389webappsphp02 Oct 2014
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALunder attackremotelinux02 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotelinux02 Oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotelinux02 Oct 2014
20RISK
open
Exploit-DBVexDay Proof
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALunder attackremotelinux02 Oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
Exploit-DBVexDay Proof
Bacula-Web 5.2.10 - 'joblogs.php?jobid' SQL Injection
CVE-2014-8295webappsphp02 Oct 2014
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DBVexDay Proof
ManageEngine OpManager / Social IT - Arbitrary File Upload (Metasploit)
CVE-2014-6034remotejava02 Oct 2014
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in Z
60RISK
open
Exploit-DBVexDay Proof
TestLink 1.9.11 - Multiple SQL Injections
CVE-2014-5308webappsphp02 Oct 2014
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-6271CRITICALunder attackwebappscgi01 Oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.