Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2010-4968
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote
23RISK
open
Referência
CVE-2026-57951
Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table
41RISK
open
Referência
CVE-2026-13579
itsourcecode Hospital Management System patientchangepassword.php sql injection
33RISK
open
ReferênciaVexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RISK
open
Referência
CVE-2010-4968
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
IP Reg 0.4 - Blind SQL Injection
CVE-2008-4523webappsphp
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2008-4525
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RISK
open
ReferênciaVexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
CVE-2008-4570webappsphp
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
CVE-2006-4716webappsphp
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RISK
open
Referência
CVE-2016-20078
WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
33RISK
open
Referência
CVE-2016-20077
WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php
33RISK
open
Referência
CVE-2016-20076
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
41RISK
open
Referência
CVE-2016-20075
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
41RISK
open
Referência
CVE-2016-20074
WordPress Lazy Content Slider Plugin 3.4 CSRF
33RISK
open
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
Referência
CVE-2010-4969
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISK
open
ReferênciaVexDay Proof
Chilkat Mail ActiveX 7.8 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4584remotewindows
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RISK
open
ReferênciaVexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RISK
open
ReferênciaVexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RISK
open
ReferênciaVexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
CVE-2008-4591webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
23RISK
open
ReferênciaVexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
CVE-2008-4592webappsphp
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RISK
open
ReferênciaVexDay Proof
Mosaic Commerce - 'cid' SQL Injection
CVE-2008-4599webappsphp
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
CVE-2008-4603webappsphp
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4604webappsphp
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
previouspage 290 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.