Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
21,554 exploits
ReferênciaVexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
CVE-2006-4239webappsphp
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISK
open
Referência
CVE-2021-36520
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RISK
open
ReferênciaVexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
CVE-2006-4644webappsphp
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISK
open
Referência
CVE-2018-8584
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
23RISK
open
ReferênciaVexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
CVE-2006-6643doswindows
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISK
open
Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
ReferênciaVexDay Proof
photokron 1.7 - Remote Database Disclosure
CVE-2008-0297webappsphp
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISK
open
ReferênciaVexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1557webappsphp
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISK
open
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISK
open
ReferênciaVexDay Proof
Noticeware E-mail Server 5.1.2.2 - 'POP3' Denial of Service
CVE-2008-6185doswindows
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 reques
23RISK
open
Referência
CVE-2010-2340
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attacker
23RISK
open
Referência
CVE-2010-2505
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash)
23RISK
open
Referência
CVE-2010-2342
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers
23RISK
open
Referência
CVE-2019-1364
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2025-34121
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RISK
open
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISK
open
Referência
CVE-2009-20007
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISK
open
Referência
CVE-2009-3366
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di
23RISK
open
ReferênciaVexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISK
open
Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2007-3529
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RISK
open
Referência
CVE-2018-12912
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RISK
open
ReferênciaVexDay Proof
WTools 0.0.1a - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-4764webappsphp
PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6781webappsphp
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open
ReferênciaVexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
CVE-2007-0307webappsphp
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
CVE-2007-1130webappsphp
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3434webappsphp
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RISK
open
previouspage 232 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.