Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
ArcaVir 2009 < 9.4.320X.9 - 'ps_drv.sys' Local Privilege Escalation
CVE-2009-1824localwindows
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet
23RISK
open
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1825webappsphp
modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated u
23RISK
open
ReferênciaVexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1826webappsphp
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote aut
23RISK
open
ReferênciaVexDay Proof
Winamp 5.55 - MAKI script Universal Integer Overflow
CVE-2009-1831localwindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open
ReferênciaVexDay Proof
Easy Px 41 CMS 09.00.00B1 - 'fiche' Local File Inclusion
CVE-2009-1847webappsphp
Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
MyForum 1.3 - Authentication Bypass
CVE-2009-1852webappsphp
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Kensei Board 2.0.0b - Multiple SQL Injections
CVE-2009-1853webappsphp
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attac
23RISK
open
ReferênciaVexDay Proof
Million Dollar Text Links 1.x - Insecure Cookie Handling
CVE-2009-1854webappsphp
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open
ReferênciaVexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
CVE-2009-1873remotewindows
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RISK
open
ReferênciaVexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
CVE-2009-1915doswindows
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
DNS Tools (PHP Digger) - Remote Command Execution
CVE-2009-1916webappsphp
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISK
open
ReferênciaVexDay Proof
CPCommerce 1.2.x - 'GLOBALS[prefix]' Arbitrary File Inclusion
CVE-2009-1936CRITICALwebappsphp
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called direc
60RISK
open
ReferênciaVexDay Proof
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
CVE-2009-1950webappsasp
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1951webappsphp
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RISK
open
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1952webappsphp
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RISK
open
ReferênciaVexDay Proof
Apache mod_dav / svn - Remote Denial of Service
CVE-2009-1955dosmultiple
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RISK
open
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISK
open
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISK
open
ReferênciaVexDay Proof
Password Protector SD 1.3.1 - Insecure Cookie Handling
CVE-2009-2003webappsphp
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RISK
open
ReferênciaVexDay Proof
Family Connections CMS 1.9 - SQL Injection
CVE-2009-2010webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authen
23RISK
open
ReferênciaVexDay Proof
Worldweaver DX Studio Player < 3.0.29.1 Firefox plugin - Command Injection
CVE-2009-2011remotewindows
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISK
open
ReferênciaVexDay Proof
Frontis 3.9.01.24 - 'source_class' SQL Injection
CVE-2009-2013webappsphp
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Virtue Shopping Mall - 'cid' SQL Injection
CVE-2009-2016webappsphp
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
YNP Portal System 2.2.0 - 'showpage.cgi p' Remote File Disclosure
CVE-2007-4256webappscgi
Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary f
23RISK
open
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.ply' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.spr' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
Prozilla Pub Site Directory - 'Directory.php?cat' SQL Injection
CVE-2007-4258webappsphp
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
CVE-2007-4279webappsphp
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RISK
open
ReferênciaVexDay Proof
Virtue Book Store - 'cid' SQL Injection
CVE-2009-2017webappsphp
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2019webappsphp
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
previouspage 133 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.