Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
iScripts AutoHoster - 'main_smtp.php' Traversal
CVE-2013-7190webappsphp15 Dec 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'additionalsettings.php' SQL Injection
CVE-2013-7189webappsphp15 Dec 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'tmpid' Local File Inclusion
CVE-2013-7190webappsphp15 Dec 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISK
open
Exploit-DBVexDay Proof
iScripts AutoHoster - 'fname' Local File Inclusion
CVE-2013-7190webappsphp15 Dec 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RISK
open
Exploit-DBVexDay Proof
Nagios XI - 'tfPassword' SQL Injection
CVE-2013-6875remotephp13 Dec 2013
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allo
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Projoom NovaSFH 3.0.2 - 'upload.php' Arbitrary File Upload
CVE-2014-1214webappsphp13 Dec 2013
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Dynamic Biz Website Builder (QuickWeb) 1.0 - '/apps/news-events/newdetail.asp?id' SQL Injection
CVE-2013-7192webappsasp13 Dec 2013
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Dynamic Biz Website Builder 'QuickWeb' 1.0 - '/login.asp' Multiple Field SQL Injections / Authentication Bypass
CVE-2013-7192webappsasp13 Dec 2013
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Cisco Unified Communications Manager - TFTP Service
CVE-2013-7030HIGHlocalhardware12 Dec 2013
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RISK
open
Exploit-DBVexDay Proof
IcoFX 2.5.0.0 - '.ico' Buffer Overflow (PoC)
CVE-2013-4988doswindows11 Dec 2013
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RISK
open
Exploit-DBVexDay Proof
eduTrac - 'showmask' Directory Traversal
CVE-2013-7097webappsphp11 Dec 2013
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar
23RISK
open
Exploit-DBVexDay Proof
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
CVE-2013-0632CRITICALunder attackremotemultiple11 Dec 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RISK
open
Exploit-DBVexDay Proof
eFront 3.6.14 (build 18012) - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2013-7194webappsphp11 Dec 2013
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RISK
open
Exploit-DBVexDay Proof
vBulletin 5 - 'index.php/ajax/api/reputation/vote?nodeid' SQL Injection (Metasploit)
CVE-2013-3522remotephp11 Dec 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RISK
open
Exploit-DBVexDay Proof
RedHat Piranha - Remote Security Bypass
CVE-2013-6492remotelinux11 Dec 2013
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac
23RISK
open
Exploit-DBVexDay Proof
HP LoadRunner EmulationAdmin - Web Service Directory Traversal (Metasploit)
CVE-2013-4837remotewindows11 Dec 2013
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RISK
open
Exploit-DBVexDay Proof
Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure
CVE-2013-4579remotelinux10 Dec 2013
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12
28RISK
open
Exploit-DBVexDay Proof
GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
CVE-2013-6356localwindows09 Dec 2013
20RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Download Manager Free & Pro 2.5.8 - Persistent Cross-Site Scripting
CVE-2013-7319webappsphp08 Dec 2013
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
Enorth Webpublisher CMS - 'thisday' SQL Injection
CVE-2013-6985webappsphp06 Dec 2013
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows
23RISK
open
Exploit-DBVexDay Proof
Zimbra 2009-2013 - Local File Inclusion
CVE-2013-7091webappslinux06 Dec 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISK
open
Exploit-DBVexDay Proof
Steinberg MyMp3PRO 5.0 - Local Buffer Overflow (SEH) (DEP Bypass + ROP)
CVE-2013-7186localwindows04 Dec 2013
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open
Exploit-DBVexDay Proof
MySQL 5.0.x - IF Query Handling Remote Denial of Service
CVE-2007-2583doslinux04 Dec 2013
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RISK
open
Exploit-DBVexDay Proof
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
CVE-2013-5486remotejava03 Dec 2013
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RISK
open
Exploit-DBVexDay Proof
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
CVE-2013-3906HIGHunder attackremotewindows03 Dec 2013
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'NDPROXY' SYSTEM Privilege Escalation (MS14-002)
CVE-2013-5065HIGHunder attacklocalwindows03 Dec 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RISK
open
Exploit-DBVexDay Proof
Chamilo Lms 1.9.6 - 'profile.php?password' SQL Injection
CVE-2013-6787webappsphp03 Dec 2013
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Formcraft - SQL Injection
CVE-2013-7187webappsphp02 Dec 2013
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
CVE-2013-3934localwindows30 Nov 2013
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
CVE-2013-0640HIGHunder attacklocalwindows28 Nov 2013
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.