Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
CVE-2008-4713webappsphp
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.chm' Denial of Service (HTML Compiled)
CVE-2009-0119doswindows
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and
35RISK
open
ReferênciaVexDay Proof
MyioSoft Ajax Portal 3.0 - 'page' SQL Injection
CVE-2009-1509webappsphp
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow (2)
CVE-2007-3148remotewindows
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
28RISK
open
ReferênciaVexDay Proof
Joomla! Component JPad 1.0 - (Authenticated) SQL Injection
CVE-2008-4715webappsphp
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
PHP Real Estate Classifieds - Remote File Inclusion
CVE-2007-3160webappsphp
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote at
23RISK
open
ReferênciaVexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
CVE-2008-4716webappsphp
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
The Gemini Portal 4.7 - 'lang' Remote File Inclusion
CVE-2008-4720webappsphp
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
CVE-2008-4732webappsphp
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RISK
open
ReferênciaVexDay Proof
PlugSpace 0.1 - 'navi' Local File Inclusion
CVE-2008-4739webappsphp
Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
KVIrc 3.4.0 - Virgo Remote Format String (PoC)
CVE-2008-4748doswindows
Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC UR
23RISK
open
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4749remotewindows
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laborato
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_extplorer 2.0.0 RC2 - Local Directory Traversal
CVE-2008-4764webappsphp
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
43RISK
open
ReferênciaVexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
CVE-2008-4773webappsphp
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Showimages - 'galid' SQL Injection
CVE-2008-4778webappsphp
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
KwsPHP 1.0 Member_Space Module - SQL Injection
CVE-2007-4956webappsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RISK
open
ReferênciaVexDay Proof
KwsPHP 1.0 stats Module - SQL Injection
CVE-2007-4956webappsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RISK
open
ReferênciaVexDay Proof
TugZip 3.00 Archiver - '.zip' Local Buffer Overflow
CVE-2008-4779localwindows
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISK
open
ReferênciaVexDay Proof
GForge < 4.6b2 - 'skill_delete' SQL Injection
CVE-2007-4966webappsphp
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
MyKtools 2.4 - 'langage' Local File Inclusion
CVE-2008-4781webappsphp
Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
e107 Plugin alternate_profiles - 'id' SQL Injection
CVE-2008-4785webappsphp
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack
23RISK
open
ReferênciaVexDay Proof
e107 Plugin EasyShop - 'category_id' Blind SQL Injection
CVE-2008-4786webappsphp
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - 'idresa' SQL Injection
CVE-2008-6633webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idre
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2008-4841doswindows
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows r
35RISK
open
ReferênciaVexDay Proof
Sepal SPBOARD 4.5 - 'board.cgi' Remote Command Execution
CVE-2008-4873webappscgi
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the fil
23RISK
open
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4874remotehardware
The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service
23RISK
open
ReferênciaVexDay Proof
PacerCMS 0.6 - 'last_module' Remote Code Execution
CVE-2007-5056webappsphp
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.