Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
phpBB News Defilante Horizontale 4.1.1 - Remote File Inclusion
CVE-2006-5415webappsphp
PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and ear
23RISK
open
ReferênciaVexDay Proof
phpBB SearchIndexer Mod - 'archive_topic.php' Remote File Inclusion
CVE-2006-5418webappsphp
PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer)
23RISK
open
ReferênciaVexDay Proof
Specimen Image Database - 'client.php' Remote File Inclusion
CVE-2006-5419webappsphp
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when regis
23RISK
open
ReferênciaVexDay Proof
Acunetix WVS 4.0 20060717 - HTTP Sniffer Component Remote Denial of Service
CVE-2007-0120doswindows
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of ser
23RISK
open
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2007-0144webappsasp
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authent
23RISK
open
ReferênciaVexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
L2J Statistik Script 0.09 - 'index.php' Local File Inclusion
CVE-2007-0173webappsphp
Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enable
23RISK
open
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
CVE-2008-0748remotewindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISK
open
ReferênciaVexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
CVE-2007-0873webappsphp
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RISK
open
ReferênciaVexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
CVE-2007-0881webappsphp
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
CVE-2008-0782webappsphp
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via
28RISK
open
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISK
open
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RISK
open
ReferênciaVexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RISK
open
ReferênciaVexDay Proof
nuBoard 0.5 - 'ssid' SQL Injection
CVE-2008-0796webappsphp
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Quiz 0.81 - 'tid' SQL Injection
CVE-2008-0799webappsphp
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows
23RISK
open
ReferênciaVexDay Proof
Joomla! Component paxxgallery 0.2 - 'iid' SQL Injection
CVE-2008-0801webappsphp
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow
23RISK
open
ReferênciaVexDay Proof
LookStrike Lan Manager 0.9 - Local/Remote File Inclusion
CVE-2008-0803webappsphp
Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbit
35RISK
open
ReferênciaVexDay Proof
Thecus N5200Pro NAS Server Control Panel - Remote File Inclusion
CVE-2008-0804remotehardware
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISK
open
ReferênciaVexDay Proof
mxBB Module mx_modsdb 1.0 - Remote File Inclusion
CVE-2006-6560webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Po
23RISK
open
ReferênciaVexDay Proof
AR Memberscript - 'usercp_menu.php' Remote File Inclusion
CVE-2006-6590webappsphp
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board 3.0.x - Blind SQL Injection
CVE-2008-0857webappsphp
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
CVE-2008-0871remotewindows
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISK
open
ReferênciaVexDay Proof
XOOPS Module Classifieds - 'cid' SQL Injection
CVE-2008-0873webappsphp
SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
CVE-2008-0878webappsphp
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
CVE-2008-0881webappsphp
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitr
23RISK
open
previouspage 112 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.