Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
21,493 exploits
ReferênciaVexDay Proof
JobSitePro 1.0 - 'search.php' SQL Injection
CVE-2007-1428webappsphp
SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Camportail 1.1 - 'camid' SQL Injection
CVE-2007-1808webappsphp
SQL injection vulnerability in show.php in the Camportail 1.1 and earlier module for Xoops allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Photo Rating 2.0 - SQL Injection
CVE-2007-1619webappsphp
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
SimpNews 2.40.01 - 'newnr' SQL Injection
CVE-2007-2750webappsphp
SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
CVE-2007-1810webappsphp
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Easybe 1-2-3 Music Store - 'process.php' SQL Injection
CVE-2007-3520webappsphp
SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Realtor 747 - 'index.php?categoryId' SQL Injection
CVE-2007-3810webappsphp
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
GameSiteScript 3.1 - profile id SQL Injection
CVE-2007-3631webappsphp
SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_gmaps 1.00 - 'mapId' SQL Injection
CVE-2007-4128webappsphp
SQL injection vulnerability in index.php in the Firestorm Technologies GMaps (com_gmaps) 1.00 component for Joomla! allo
23RISK
open
ReferênciaVexDay Proof
A-Blog 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-0676webappsphp
Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2012-10050
CuteFlow <= 2.11.2 Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2012-10050
CuteFlow <= 2.11.2 Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2012-10050
CuteFlow <= 2.11.2 Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2010-0762
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2010-0762
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2016-10156
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RISK
open
Referência
CVE-2016-4578
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local us
23RISK
open
ReferênciaVexDay Proof
MyNewsGroups 0.6b - 'myng_root' Remote Inclusion
CVE-2006-3966webappsphp
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsG
23RISK
open
ReferênciaVexDay Proof
Mambo Component 'com_colophon' 1.2 - Remote File Inclusion
CVE-2006-3969webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and
23RISK
open
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RISK
open
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'file_path' Remote File Inclusion
CVE-2006-3991webappsphp
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
TSEP 0.942 - 'copyright.php' Remote File Inclusion
CVE-2006-3993webappsphp
PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows
23RISK
open
ReferênciaVexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RISK
open
Referência
CVE-2006-3995
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RISK
open
ReferênciaVexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
CVE-2006-3995webappsphp
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RISK
open
ReferênciaVexDay Proof
AV Arcade 2.1b - 'index.php?id' SQL Injection
CVE-2007-3563webappsphp
SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
CVE-2008-1176webappsphp
Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remot
23RISK
open
ReferênciaVexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2980webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary
23RISK
open
previouspage 165 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.