Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
CVE-2009-0461webappsphp
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RISK
open
ReferênciaVexDay Proof
ClickCart 6.0 - Authentication Bypass
CVE-2009-0462webappsphp
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
Axiom Photo/News Gallery 0.8.6 - Remote File Inclusion
CVE-2007-0200webappsphp
PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 a
23RISK
open
ReferênciaVexDay Proof
GLLCTS2 - 'sort' Blind SQL Injection
CVE-2008-2919webappsphp
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0468remotewindows
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RISK
open
ReferênciaVexDay Proof
AgerMenu 0.01 - 'top.inc.php?rootdir' Remote File Inclusion
CVE-2007-0837webappsphp
PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
NUNE News Script 2.0pre2 - Multiple Remote File Inclusions
CVE-2007-0143webappsphp
Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
minb 0.1.0 - Remote Code Execution
CVE-2008-7005webappsphp
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
CVE-2007-1118webappsphp
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Expert Advisior - 'index.php?id' SQL Injection
CVE-2007-3882webappsphp
SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
CVE-2008-6253webappsphp
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Portfol 1.2 - 'vcatid' SQL Injection
CVE-2009-0494webappsphp
SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Demo4 CMS - 'id' SQL Injection
CVE-2008-2983webappsphp
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
CVE-2006-6740webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
CVE-2007-3612remotewindows
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RISK
open
ReferênciaVexDay Proof
Virtual Guestbook 2.1 - Remote Database Disclosure
CVE-2009-0498webappsasp
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0466webappsasp
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
CVE-2006-3748webappsphp
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RISK
open
ReferênciaVexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-0529webappsphp
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-0530webappsphp
Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remot
23RISK
open
ReferênciaVexDay Proof
A Better Member-Based ASP Photo Gallery - 'entry' SQL Injection
CVE-2009-0531webappsphp
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote atta
23RISK
open
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player Control - Remote Buffer Overflow
CVE-2008-1044remotewindows
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QS
23RISK
open
ReferênciaVexDay Proof
Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow
CVE-2008-3155remotewindows
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac
23RISK
open
ReferênciaVexDay Proof
WebXell Editor 0.1.3 - Arbitrary File Upload
CVE-2008-3178webappsphp
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
CafeEngine - 'catid' SQL Injection
CVE-2009-0574webappsphp
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Winamp 5.21 - '.Midi' File Header Handling Buffer Overflow (PoC)
CVE-2006-3228doswindows
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary
28RISK
open
ReferênciaVexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
CVE-2007-5653localwindows
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RISK
open
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
CVE-2008-0661doswindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISK
open
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISK
open
previouspage 135 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.