Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open
ReferênciaVexDay Proof
PHPEasyNews 1.13 RC2 - 'POST' SQL Injection
CVE-2008-2823webappsphp
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1347webappsphp
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
CVE-2006-2686webappsphp
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RISK
open
ReferênciaVexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
CVE-2006-7069webappsphp
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
CVE-2007-1224remotewindows
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RISK
open
ReferênciaVexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0473webappsasp
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RISK
open
ReferênciaVexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
CVE-2008-1713doswindows
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RISK
open
ReferênciaVexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
CVE-2008-2834webappsphp
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0453webappsphp
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RISK
open
ReferênciaVexDay Proof
DMXReady Registration Manager 1.1 - Database Disclosure
CVE-2009-1821webappsasp
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, whic
23RISK
open
ReferênciaVexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
CVE-2006-4300webappsasp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2681webappsphp
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open
ReferênciaVexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open
ReferênciaVexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
CVE-2008-2856webappsphp
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
CVE-2006-4891webappsasp
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5774webappsphp
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RISK
open
ReferênciaVexDay Proof
PHP Webquest 2.6 - Get Database Credentials
CVE-2008-0249webappsphp
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RISK
open
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2863webappsphp
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RISK
open
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4115webappsphp
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RISK
open
ReferênciaVexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
CVE-2008-5773webappsasp
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
CVE-2008-6269webappsphp
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RISK
open
ReferênciaVexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
CVE-2008-7007webappsphp
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1726webappsphp
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RISK
open
ReferênciaVexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
CVE-2008-4484webappsphp
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RISK
open
previouspage 104 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.