Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
CVE-2006-4158webappsphp
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
ACGV News 0.9.1 - 'article.php' Remote File Inclusion
CVE-2006-4638webappsphp
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
CVE-2006-4719webappsphp
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
CVE-2006-5306webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISK
open
Referência
CVE-2017-2508
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
CVE-2007-3790dosmultiple
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RISK
open
ReferênciaVexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
CVE-2008-5840webappsphp
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RISK
open
Referência
CVE-2017-17870
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open
Referência
CVE-2018-6363
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISK
open
Referência
CVE-2018-6363
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISK
open
Referência
CVE-2017-9614
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISK
open
Referência
CVE-2017-9614
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISK
open
Referência
CVE-2010-1711
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows r
23RISK
open
Referência
CVE-2010-1711
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows r
23RISK
open
Referência
CVE-2019-0570
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windo
23RISK
open
Referência
CVE-2009-2923
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files
23RISK
open
Referência
CVE-2012-5387
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP
23RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0987webappsphp
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbit
23RISK
open
Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISK
open
Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISK
open
ReferênciaVexDay Proof
Link Request Contact Form 3.4 - Remote Code Execution
CVE-2007-3199webappsphp
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
CVE-2007-5646webappsphp
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RISK
open
ReferênciaVexDay Proof
PowerPHPBoard 1.00b - Multiple Local File Inclusions
CVE-2008-1534webappsphp
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitr
23RISK
open
ReferênciaVexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
CVE-2008-3237webappsphp
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
easysite 2.3 - Multiple Vulnerabilities
CVE-2008-4155webappsphp
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire
23RISK
open
ReferênciaVexDay Proof
PowerPortal 2.0.13 - 'path' Local Directory Traversal
CVE-2008-4361webappsphp
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary file
23RISK
open
Referência
CVE-2009-4423
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
previouspage 341 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.