Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISK
open
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISK
open
ReferênciaVexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
CVE-2007-6126webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
CVE-2007-6128webappsphp
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
CVE-2007-6137webappsphp
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Plogger 3.0 - SQL Injection
CVE-2008-3563webappsphp
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
CCProxy 6.2 - 'ping' Remote Buffer Overflow
CVE-2004-2685remotewindows
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open
ReferênciaVexDay Proof
CCProxy 6.2 - Telnet Proxy Ping Overflow (Metasploit)
CVE-2004-2685remotewindows
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open
ReferênciaVexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
CVE-2007-6369webappsphp
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RISK
open
ReferênciaVexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
CVE-2008-5641webappsphp
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
CVE-2008-5643webappsphp
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6490webappsphp
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a passw
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6496webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RISK
open
ReferênciaVexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
CVE-2008-5648webappsphp
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
CVE-2008-5666doswindows
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6497webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6503webappsasp
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
CVE-2008-5752webappsphp
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RISK
open
ReferênciaVexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
CVE-2008-5753doswindows
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RISK
open
ReferênciaVexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
CVE-2008-0157webappsphp
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open
ReferênciaVexDay Proof
Gateway WebLaunch - ActiveX Remote Buffer Overflow
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open
ReferênciaVexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
CVE-2008-0230webappsphp
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RISK
open
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0232webappsphp
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
CVE-2008-0310localsco
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RISK
open
ReferênciaVexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
CVE-2008-0332webappsphp
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
CVE-2008-0355webappsphp
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISK
open
previouspage 178 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.