Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
CVE-2008-3366webappsphp
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3720webappsphp
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
MyCard 1.0.2 - 'id' SQL Injection
CVE-2008-4738webappsphp
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AIOCP 1.4 - 'poll_id' SQL Injection
CVE-2008-4782webappsphp
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RISK
open
ReferênciaVexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
CVE-2008-5774webappsasp
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Mediatheka 4.2 - Blind SQL Injection
CVE-2008-5895webappsphp
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RISK
open
ReferênciaVexDay Proof
EasyWay CMS - 'mid' SQL Injection
CVE-2008-2555webappsphp
SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
GLLCTS2 < 4.2.4 - 'detail' SQL Injection
CVE-2008-2746webappsphp
SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
CVE-2007-4581webappsphp
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.1 - 'table' SQL Injection
CVE-2007-5719webappsphp
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
HoMaP-CMS 0.1 - 'go' SQL Injection
CVE-2008-2989webappsphp
SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
MMSLamp - 'idpro' SQL Injection
CVE-2007-6575webappsphp
SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
pLink 2.07 - 'linkto.php' Blind SQL Injection
CVE-2008-4357webappsphp
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
ClipShare - 'UID' SQL Injection
CVE-2008-0089webappsphp
SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
ReferênciaVexDay Proof
DESlock+ 3.2.7 - 'vdlptokn.sys' Local Denial of Service
CVE-2008-4362doswindows
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (syst
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Autoresponder Hosting - 'tr.php' SQL Injection
CVE-2008-4882webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
WebCal - 'webCal3_detail.asp?event_id' SQL Injection
CVE-2009-1945webappsphp
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Open Biller 0.1 - 'Username' Blind SQL Injection
CVE-2009-2036webappsphp
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' SQL Injection
CVE-2008-3213webappsphp
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Mambo Component 'com_a6mambohelpdesk' 18RC1 - Remote File Inclusion
CVE-2006-3930webappsphp
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlie
23RISK
open
ReferênciaVexDay Proof
AstroSPACES 1.1.1 - 'id' SQL Injection
CVE-2008-4642webappsphp
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Jamit Job Board 3.x - Blind SQL Injection
CVE-2008-5295webappsphp
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
E-topbiz Number Links 1 - 'id' SQL Injection
CVE-2008-5804webappsphp
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
SFS EZ Auction - Blind SQL Injection
CVE-2008-6778webappsphp
SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
SFS EZ Pub Site - SQL Injection
CVE-2008-6794webappsphp
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6883webappsphp
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection
CVE-2008-4518webappsphp
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Riddles Complete Website 1.2.1 - 'riddleid' SQL Injection
CVE-2008-5166webappsphp
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL comm
23RISK
open
previouspage 149 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.