Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Skype Extension for Firefox Beta 2.2.0.95 - Clipboard Writing
CVE-2008-5697remotewindows
The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitra
23RISK
open
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6087webappsphp
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Uploader 1.1 - 'Filename' File Disclosure
CVE-2008-7178webappsphp
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
CVE-2009-1744localwindows
InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote
23RISK
open
ReferênciaVexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
CVE-2007-2889webappsphp
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
CVE-2008-2018webappsphp
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
CVE-2007-4046webappsphp
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISK
open
ReferênciaVexDay Proof
DreamNews Manager - 'id' SQL Injection
CVE-2008-3189webappsphp
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
CVE-2007-4637webappsphp
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RISK
open
ReferênciaVexDay Proof
P2P Foxy - Out of Memory Denial of Service
CVE-2008-6742doswindows
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RISK
open
ReferênciaVexDay Proof
Papoo CMS 3.x - 'pfadhier' Local File Inclusion
CVE-2009-0735webappsphp
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled an
23RISK
open
ReferênciaVexDay Proof
MySpeach 2.1b - 'up.php' Remote File Inclusion
CVE-2007-0498webappsphp
PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5053webappsphp
Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5641webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers t
35RISK
open
ReferênciaVexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
CVE-2008-3191webappsphp
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RISK
open
ReferênciaVexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-1450webappsphp
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Shop-Script 2.0 - 'index.php' Remote File Disclosure
CVE-2008-0158webappsphp
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
zFeeder 1.6 - 'admin.php' Admin Bypass
CVE-2009-0807webappsphp
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
23RISK
open
ReferênciaVexDay Proof
phpBB Ajax Shoutbox 0.0.5 - Remote File Inclusion
CVE-2006-5312webappsphp
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows r
23RISK
open
ReferênciaVexDay Proof
MiniGal b13 - Remote Code Execution
CVE-2007-2145webappsphp
The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a fil
23RISK
open
ReferênciaVexDay Proof
VWar 1.5.0 R15 - 'mvcw.php' Remote File Inclusion
CVE-2007-4605webappsphp
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
CVE-2008-2857webappsphp
AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent a
23RISK
open
ReferênciaVexDay Proof
Zix Forum 1.12 - 'layid' SQL Injection
CVE-2006-2541webappsasp
SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
AyeView 2.20 - '.GIF' Image Local Crash
CVE-2008-5884doswindows
AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malfo
23RISK
open
ReferênciaVexDay Proof
MKPortal 1.1.1 reviews / Gallery modules - SQL Injection
CVE-2007-3814webappsphp
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1
23RISK
open
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-6193webappsphp
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain se
23RISK
open
ReferênciaVexDay Proof
Vanilla 1.1.3 - Blind SQL Injection
CVE-2007-5644webappsphp
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortrol
23RISK
open
ReferênciaVexDay Proof
Scribe 0.2 - 'index.php' Local File Inclusion
CVE-2008-0822webappsphp
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a
23RISK
open
ReferênciaVexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
CVE-2009-1677webappsphp
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 an
23RISK
open
ReferênciaVexDay Proof
Online Grades & Attendance 3.2.6 - Multiple Local File Inclusions
CVE-2009-2037webappsphp
Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when r
23RISK
open
previouspage 113 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.