Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Aratix 0.2.2b11 - '/inc/init.inc.php' Remote File Inclusion
CVE-2007-0135webappsphp
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
L2J Statistik Script 0.09 - 'index.php' Local File Inclusion
CVE-2007-0173webappsphp
Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enable
23RISK
open
ReferênciaVexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0225webappsasp
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
Astanda Directory Project 1.2 - 'link_id' SQL Injection
CVE-2008-0649webappsphp
SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RISK
open
ReferênciaVexDay Proof
Mihalism Multi Host Download - 'Username' Blind SQL Injection
CVE-2008-0714webappsphp
SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Mambo Component Sermon 0.2 - 'gid' SQL Injection
CVE-2008-0721webappsphp
SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0737webappsasp
SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x version
23RISK
open
ReferênciaVexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
CVE-2008-0745webappsphp
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
CVE-2008-0748remotewindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISK
open
ReferênciaVexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
CVE-2007-0873webappsphp
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RISK
open
ReferênciaVexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
CVE-2007-0881webappsphp
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
CVE-2008-0782webappsphp
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via
28RISK
open
ReferênciaVexDay Proof
AuraCMS 1.62 - Multiple SQL Injections
CVE-2008-0811webappsphp
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1)
23RISK
open
ReferênciaVexDay Proof
XPWeb 3.3.2 - 'url' Remote File Disclosure
CVE-2008-0813webappsphp
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote atta
23RISK
open
ReferênciaVexDay Proof
TRUC 0.11.0 - 'download.php' Remote File Disclosure
CVE-2008-0814webappsphp
Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attac
23RISK
open
ReferênciaVexDay Proof
Apple iOS 4.0.3 - DPAP Server Denial of Service
CVE-2008-0830dosios
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (c
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.5 - SQL Injection
CVE-2008-0831webappsphp
Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! all
23RISK
open
ReferênciaVexDay Proof
Mambo Component Ricette 1.0 - SQL Injection
CVE-2008-0841webappsphp
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_clasifier - 'cat_id' SQL Injection
CVE-2008-0842webappsphp
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'user_id' SQL Injection
CVE-2008-0844webappsphp
SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISK
open
ReferênciaVexDay Proof
AR Memberscript - 'usercp_menu.php' Remote File Inclusion
CVE-2006-6590webappsphp
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board 3.0.x - Blind SQL Injection
CVE-2008-0857webappsphp
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
CVE-2008-0871remotewindows
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISK
open
ReferênciaVexDay Proof
XOOPS Module Classifieds - 'cid' SQL Injection
CVE-2008-0873webappsphp
SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
CVE-2008-0878webappsphp
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
CVE-2008-0881webappsphp
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitr
23RISK
open
previouspage 175 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.