Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RISK
open
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' SQL Injection
CVE-2008-3213webappsphp
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Mambo Component 'com_a6mambohelpdesk' 18RC1 - Remote File Inclusion
CVE-2006-3930webappsphp
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlie
23RISK
open
ReferênciaVexDay Proof
AstroSPACES 1.1.1 - 'id' SQL Injection
CVE-2008-4642webappsphp
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Jamit Job Board 3.x - Blind SQL Injection
CVE-2008-5295webappsphp
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
E-topbiz Number Links 1 - 'id' SQL Injection
CVE-2008-5804webappsphp
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
SFS EZ Auction - Blind SQL Injection
CVE-2008-6778webappsphp
SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
SFS EZ Pub Site - SQL Injection
CVE-2008-6794webappsphp
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6883webappsphp
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection
CVE-2008-4518webappsphp
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Riddles Complete Website 1.2.1 - 'riddleid' SQL Injection
CVE-2008-5166webappsphp
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
PG Job Site - Blind SQL Injection
CVE-2008-6117webappsphp
SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
phpBB 3 - Mod Tag Board 4 Blind SQL Injection
CVE-2008-6314webappsphp
SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - Authentication Bypass
CVE-2008-6623webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
ReferênciaVexDay Proof
Pre Podcast Portal - SQL Injection
CVE-2008-6230webappsphp
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AvailScript Photo Album - 'pics.php' Multiple Vulnerabilities
CVE-2008-4369webappsphp
SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
AvailScript Article Script - 'articles.php' Multiple Vulnerabilities
CVE-2008-4371webappsphp
SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_bayesiannaivefilter 1.1 - Remote File Inclusion
CVE-2006-3962webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaiv
23RISK
open
ReferênciaVexDay Proof
FOSS Gallery Public 1.0 - Arbitrary File Upload (PoC)
CVE-2008-4509webappsphp
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows
23RISK
open
ReferênciaVexDay Proof
Galerie 3.2 - 'pic' WBB Lite Addon Blind SQL Injection
CVE-2008-4516webappsphp
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Mod raidtracker_panel - 'INFO_RAID_ID' SQL Injection
CVE-2008-4521webappsphp
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module
23RISK
open
ReferênciaVexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RISK
open
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RISK
open
ReferênciaVexDay Proof
Joomla! Component actualite 1.0 - 'id' SQL Injection
CVE-2008-4617webappsphp
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Meeting Room Booking System (MRBS) < 1.4 - SQL Injection
CVE-2008-4620webappsphp
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
NewsLetter 3.5 - 'NL_PATH' Remote File Inclusion
CVE-2006-3986webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers
23RISK
open
previouspage 166 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.