Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHP ZLink 0.3 - 'go.php' SQL Injection
CVE-2007-6578webappsphp
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Wallpaper Site 1.0.09 - 'category.php' SQL Injection
CVE-2007-6580webappsphp
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
CVE-2007-6584webappsphp
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
CVE-2007-6585webappsphp
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
CVE-2007-6605doswindows
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
LulieBlog 1.02 - SQL Injection
CVE-2008-0446webappsphp
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
CVE-2007-6615webappsphp
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6622webappsphp
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
IPTBB 0.5.4 - 'id' SQL Injection
CVE-2007-6639webappsphp
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
oneSCHOOL - 'admin/login.asp' SQL Injection
CVE-2007-6665webappsasp
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
ZenPhoto 1.1.3 - 'rss.php?albumnr' SQL Injection
CVE-2007-6666webappsphp
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Forum Host 3.0.x - Remote File Inclusion
CVE-2007-6657webappsphp
PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier
23RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 (Final) - Multiple SQL Injections
CVE-2007-6667webappsphp
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
KGB 1.87 - Local File Inclusion / Remote Code Execution
CVE-2006-5115webappsphp
Directory traversal vulnerability in kgcall.php in KGB 1.87 allows remote attackers to include and execute arbitrary loc
23RISK
open
ReferênciaVexDay Proof
phpMyWebmin 1.0 - 'window.php' Remote File Inclusion
CVE-2006-5124webappsphp
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
phpMyWebmin 1.0 - 'window.php' Remote File Inclusion
CVE-2006-5125webappsphp
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remo
23RISK
open
ReferênciaVexDay Proof
SmallNuke 2.0.4 - Pass Recovery SQL Injection
CVE-2008-0147webappsphp
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remot
23RISK
open
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISK
open
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISK
open
ReferênciaVexDay Proof
NetRisk 1.9.7 - Cross-Site Scripting / SQL Injection
CVE-2008-0185webappsphp
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
samPHPweb 4.2.2 - 'songinfo.php' SQL Injection
CVE-2008-0187webappsphp
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote atta
23RISK
open
ReferênciaVexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
CVE-2008-0210webappsphp
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests,
23RISK
open
ReferênciaVexDay Proof
PHP Webquest 2.6 - 'id_actividad' SQL Injection
CVE-2008-0219webappsphp
SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0233webappsphp
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RISK
open
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
CVE-2008-0234doswindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISK
open
ReferênciaVexDay Proof
Microsoft Rich Textbox Control 6.0-SP6 - 'SaveFile()' Insecure Method
CVE-2008-0237remotewindows
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary command
28RISK
open
ReferênciaVexDay Proof
WU-FTPD 2.6.2 - 'wuftpd-freezer.c' Remote Denial of Service
CVE-2003-0854doslinux
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, w
23RISK
open
previouspage 170 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.