Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504webappsasp
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RISK
open
ReferênciaVexDay Proof
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
CVE-2007-6506doswindows
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlie
28RISK
open
ReferênciaVexDay Proof
eSyndiCat Link Exchange Script 2005-2006 - SQL Injection
CVE-2007-6543webappsphp
SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
LulieBlog 1.02 - SQL Injection
CVE-2008-0446webappsphp
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
CVE-2007-6615webappsphp
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6622webappsphp
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
IPTBB 0.5.4 - 'id' SQL Injection
CVE-2007-6639webappsphp
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
oneSCHOOL - 'admin/login.asp' SQL Injection
CVE-2007-6665webappsasp
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
ZenPhoto 1.1.3 - 'rss.php?albumnr' SQL Injection
CVE-2007-6666webappsphp
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Forum Host 3.0.x - Remote File Inclusion
CVE-2007-6657webappsphp
PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier
23RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 (Final) - Multiple SQL Injections
CVE-2007-6667webappsphp
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Bitweaver 2.8.1 - Multiple Vulnerabilities
CVE-2012-5193webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbi
23RISK
open
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'sort' SQL Injection
CVE-2006-5030webappsphp
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users
23RISK
open
ReferênciaVexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
Web//News 1.4 - 'parser.php' Remote File Inclusion (1)
CVE-2006-5100webappsphp
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
Site@School 2.4.10 - Blind SQL Injection
CVE-2008-0129webappsphp
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Tribisur 2.0 - SQL Injection
CVE-2008-0133webappsphp
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
DivX Player 6.6.0 - ActiveX 'SetPassword()' Denial of Service (PoC)
CVE-2008-0090doswindows
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Int
28RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
CVE-2008-0099webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Microsoft Office 2003 - '.wps' Local Stack Overflow (MS08-011)
CVE-2008-0108localwindows
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Wor
35RISK
open
ReferênciaVexDay Proof
LoudBlog 0.6.1 - 'parsedpage' Remote Code Execution
CVE-2008-0139webappsphp
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to exec
28RISK
open
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0142webappsphp
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2006-0658webappsphp
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RISK
open
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0351webappsphp
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es
23RISK
open
ReferênciaVexDay Proof
StreamAudio ChainCast ProxyManager - 'ccpm_0237.dll' Remote Buffer Overflow
CVE-2008-0248remotewindows
Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
CVE-2008-0250localwindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISK
open
ReferênciaVexDay Proof
PixelPost 1.7 - Blind SQL Injection
CVE-2008-0358webappsphp
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
CVE-2008-0379doswindows
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RISK
open
previouspage 169 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.