Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0346remotemultiple24 Apr 2014
20RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX - Local Security Bypass
CVE-2014-1322localosx22 Apr 2014
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0633remotewindows21 Apr 2014
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10
28RISK
open
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0634remotewindows21 Apr 2014
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x
60RISK
open
Exploit-DBVexDay Proof
SAP Router - Timing Attack Password Disclosure
CVE-2014-0984remotehardware17 Apr 2014
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation
23RISK
open
Exploit-DBVexDay Proof
Jzip - Buffer Overflow (PoC) (SEH Unicode)
CVE-2010-5300doswindows16 Apr 2014
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CMarkup Use-After-Free (MS14-012) (Metasploit)
CVE-2014-0322HIGHunder attackremotewindows16 Apr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RISK
open
Exploit-DBVexDay Proof
lxml - 'clean_html' Security Bypass
CVE-2014-3146MEDIUMremotelinux15 Apr 2014
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct
33RISK
open
Exploit-DBVexDay Proof
Adobe Reader for Android 11.1.3 - Arbitrary JavaScript Execution
CVE-2014-0514localandroid15 Apr 2014
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RISK
open
Exploit-DBVexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
CVE-2014-0358webappsjsp14 Apr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - CMarkup Use-After-Free (MS14-012)
CVE-2014-0322HIGHunder attackremotewindows14 Apr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RISK
open
Exploit-DBVexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
CVE-2014-0358webappsjsp14 Apr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISK
open
Exploit-DBVexDay Proof
Xangati XSR / XNR - 'gui_input_test.pl' Remote Command Execution
CVE-2014-0358webappscgi14 Apr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RISK
open
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2850remoteunix10 Apr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RISK
open
Exploit-DBVexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
CVE-2014-1761HIGHunder attacklocalwindows10 Apr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RISK
open
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0160HIGHunder attackremotemultiple10 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2849remoteunix10 Apr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RISK
open
Exploit-DBVexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
CVE-2014-2268remotephp10 Apr 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RISK
open
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0346remotemultiple10 Apr 2014
20RISK
open
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0160HIGHunder attackremotemultiple09 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0346remotemultiple09 Apr 2014
20RISK
open
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0160HIGHunder attackremotemultiple08 Apr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0346remotemultiple08 Apr 2014
20RISK
open
Exploit-DBVexDay Proof
JIRA Issues Collector - Directory Traversal (Metasploit)
CVE-2014-2314remotewindows07 Apr 2014
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RISK
open
Exploit-DBVexDay Proof
PHPFox - Access Control Security Bypass
CVE-2013-7196webappsphp05 Apr 2014
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric
23RISK
open
Exploit-DBVexDay Proof
ibstat $PATH - Local Privilege Escalation (Metasploit)
CVE-2013-4011locallinux04 Apr 2014
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RISK
open
Exploit-DBVexDay Proof
SePortal 2.5 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2008-5191remotephp31 Mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RISK
open
Exploit-DBVexDay Proof
Fitnesse Wiki - Remote Command Execution (Metasploit)
CVE-2014-1216remotewindows28 Mar 2014
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAN
23RISK
open
Exploit-DBVexDay Proof
Apache CouchDB 1.5.0 - 'uuids' Denial of Service
CVE-2014-2668dosmultiple26 Mar 2014
Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via t
28RISK
open
Exploit-DBVexDay Proof
InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injection
CVE-2014-2531webappsphp26 Mar 2014
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.