Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Apple Safari 3.2.2/4b - nested elements XML Parsing Remote Crash
CVE-2009-1233doswindows
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an
23RISK
open
ReferênciaVexDay Proof
kawf 1.0 - 'main.php' Remote File Inclusion
CVE-2006-5522webappsphp
Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.3 - Remote Command Execution
CVE-2008-1860webappsphp
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
Ultimate Fun Book 1.02 - 'function.php' Remote File Inclusion
CVE-2007-1059webappsphp
PHP remote file inclusion vulnerability in function.php in Ultimate Fun Book 1.02 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Joomla! Component DT Register - SQL Injection
CVE-2008-3265webappsphp
SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Solaris 9 (UltraSPARC) - 'sadmind' Remote Code Execution
CVE-2008-4556remotesolaris
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISK
open
ReferênciaVexDay Proof
Opera 9.64 - 7400 nested elements XML Parsing Remote Crash
CVE-2009-1234dosmultiple
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
CVE-2009-1235localosx
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
CVE-2009-1236dososx
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RISK
open
ReferênciaVexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
CVE-2008-4570webappsphp
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
CVE-2006-0099webappsphp
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RISK
open
ReferênciaVexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6112webappsphp
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
CVE-2006-6786webappsphp
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'macfsstat' Local Kernel Memory Leak/Denial of Service
CVE-2009-1237dososx
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'Profil' Kernel Memory Leak/Denial of Service (PoC)
CVE-2009-1237dososx
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open
ReferênciaVexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
CVE-2007-0638webappsphp
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RISK
open
ReferênciaVexDay Proof
Chilkat Mail ActiveX 7.8 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4584remotewindows
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RISK
open
ReferênciaVexDay Proof
Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method
CVE-2008-4586remotewindows
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macr
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.x - 'vfssysctl' Local Kernel Denial of Service (PoC)
CVE-2009-1238dososx
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows
23RISK
open
ReferênciaVexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
CVE-2006-4113webappsphp
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RISK
open
ReferênciaVexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
CVE-2006-5306webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RISK
open
ReferênciaVexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
CVE-2009-1247webappsphp
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL c
28RISK
open
ReferênciaVexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
CVE-2009-2100webappsphp
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
CVE-2007-3790dosmultiple
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RISK
open
ReferênciaVexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RISK
open
ReferênciaVexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RISK
open
ReferênciaVexDay Proof
Cartweaver 2.16.11 - 'ProdID' SQL Injection
CVE-2006-2046webappscgi
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RISK
open
ReferênciaVexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
CVE-2009-1256webappsphp
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISK
open
ReferênciaVexDay Proof
OPENi-CMS 1.0.1beta - 'config' Remote File Inclusion
CVE-2006-4750webappsphp
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, all
23RISK
open
ReferênciaVexDay Proof
KGB 1.9 - 'sesskglogadmin.php' Local File Inclusion
CVE-2007-0337webappsphp
Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and ex
23RISK
open
previouspage 147 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.