Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISK
open
ReferênciaVexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RISK
open
ReferênciaVexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-6335remotelinux
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW
28RISK
open
ReferênciaVexDay Proof
Joomla! / Mambo Component rsgallery 2.0b5 - 'catid' SQL Injection
CVE-2007-6362webappsphp
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and
23RISK
open
ReferênciaVexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
CVE-2007-6366webappsphp
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
BadBlue 2.72 - PassThru Remote Buffer Overflow
CVE-2007-6377remotewindows
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISK
open
ReferênciaVexDay Proof
phpGroupWare 0.9.16.010 - 'GLOBALS[]' Remote Code Execution
CVE-2006-4458webappsphp
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allow
23RISK
open
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISK
open
ReferênciaVexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RISK
open
ReferênciaVexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
CVE-2007-6391webappsphp
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4586webappsphp
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticat
23RISK
open
ReferênciaVexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
CVE-2006-4602webappsphp
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open
ReferênciaVexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
CVE-2007-6393webappsphp
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6395webappsphp
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6399webappsphp
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use
23RISK
open
ReferênciaVexDay Proof
Adult Script 1.6 - Unauthorized Administrative Access
CVE-2007-6414webappsphp
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which all
23RISK
open
ReferênciaVexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
CVE-2011-4908webappsphp
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISK
open
ReferênciaVexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
CVE-2006-4610webappsphp
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RISK
open
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
webSPELL 4.01.01 - Database Backup Download
CVE-2006-4782webappsphp
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authe
23RISK
open
ReferênciaVexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
CVE-2007-6459webappsphp
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open
ReferênciaVexDay Proof
Form Tools 1.5.0b - Multiple Remote File Inclusions
CVE-2007-6464webappsphp
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
FreeWebShop 2.2.1 - Blind SQL Injection
CVE-2007-6466webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
CVE-2012-1495webappsphp
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISK
open
ReferênciaVexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
CVE-2007-6475webappsphp
Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504webappsasp
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RISK
open
ReferênciaVexDay Proof
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
CVE-2007-6506doswindows
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlie
28RISK
open
ReferênciaVexDay Proof
eSyndiCat Link Exchange Script 2005-2006 - SQL Injection
CVE-2007-6543webappsphp
SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.6 - Get Admin Cookie Blind SQL Injection
CVE-2007-6544webappsphp
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
CVE-2007-6553webappsphp
Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute
23RISK
open
previouspage 148 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.