Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
Wireshark 1.10.7 - Denial of Service (PoC)
CVE-2014-5116doswindows16 May 2014
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac
23RISK
open
Exploit-DBVexDay Proof
RealPlayer - '.3gp' File Processing Memory Corruption
CVE-2014-3444dosmultiple16 May 2014
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
CIS Manager - 'email' SQL Injection
CVE-2014-3749webappsasp16 May 2014
SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
Winamp - '.flv' File Processing Memory Corruption
CVE-2014-3442doswindows16 May 2014
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RISK
open
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2014-3120HIGHunder attackwebappsmultiple15 May 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
Exploit-DBVexDay Proof
Easy File Sharing Web Server 6.8 - Remote Stack Buffer Overflow
CVE-2014-3791remotewindows14 May 2014
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RISK
open
Exploit-DBVexDay Proof
Broadcom PIPA C211 - Sensitive Information Disclosure
CVE-2014-2046webappshardware14 May 2014
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allow
23RISK
open
Exploit-DBVexDay Proof
GOM Player 2.2.57.5189 - '.ogg' Crash (PoC)
CVE-2014-3216doswindows12 May 2014
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISK
open
Exploit-DBVexDay Proof
JetAudio 8.1.1 - '.ogg' Crash (PoC)
CVE-2014-3443doswindows12 May 2014
JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - Shader Buffer Overflow (Metasploit)
CVE-2014-0515remotewindows12 May 2014
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RISK
open
Exploit-DBVexDay Proof
EFS Easy Chat Server 3.1 - Remote Stack Buffer Overflow
CVE-2004-2466remotewindows12 May 2014
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RISK
open
Exploit-DBVexDay Proof
Yokogawa CS3000 - 'BKESimmgr.exe' Remote Buffer Overflow (Metasploit)
CVE-2014-0782remotewindows12 May 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RISK
open
Exploit-DBVexDay Proof
SpiceWorks 7.2.00174 - Persistent Cross-Site Scripting
CVE-2014-3740webappswindows12 May 2014
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.1.3 - '.wav' File Memory Corruption
CVE-2014-3441dosmultiple09 May 2014
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash)
23RISK
open
Exploit-DBVexDay Proof
TOA - Cross-Site Request Forgery
CVE-2014-2989webappsphp08 May 2014
Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hij
23RISK
open
Exploit-DBVexDay Proof
Foscam IP Camera - Predictable Credentials Security Bypass
CVE-2014-1849remotehardware08 May 2014
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on pred
28RISK
open
Exploit-DBVexDay Proof
Collabtive 1.2 - SQL Injection
CVE-2014-3246webappsphp08 May 2014
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
Collabtive 1.2 - Persistent Cross-Site Scripting
CVE-2014-3247webappsphp08 May 2014
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
Caldera - '/costview2/jobs.php?tr' SQL Injection
CVE-2014-2934webappsphp07 May 2014
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
Caldera - '/costview2/printers.php?tr' SQL Injection
CVE-2014-2934webappsphp07 May 2014
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NTUserMessageCall Win32k Kernel Pool Overflow 'schlamperei.x86.dll' (MS13-053) (Metasploit)
CVE-2013-1300localwindows_x8606 May 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - Integer Underflow Remote Code Execution (Metasploit)
CVE-2014-0497HIGHunder attackremotewindows06 May 2014
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RISK
open
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple02 May 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISK
open
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple02 May 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0113remotemultiple02 May 2014
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict
45RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
CVE-2013-5331remotewindows29 Apr 2014
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RISK
open
Exploit-DBVexDay Proof
Wireshark 1.8.12/1.10.5 - wiretap/mpeg.c Stack Buffer Overflow (Metasploit)
CVE-2014-2299localwindows28 Apr 2014
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RISK
open
Exploit-DBVexDay Proof
Kolibri Web Server 2.0 - GET Stack Buffer Overflow
CVE-2014-4158remotewindows25 Apr 2014
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RISK
open
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0160HIGHunder attackremotemultiple24 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DBVexDay Proof
dompdf 0.6.0 - 'dompdf.php?read' Arbitrary File Read
CVE-2014-2383webappsphp24 Apr 2014
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.