Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RISK
open
ReferênciaVexDay Proof
NCTAudioStudio2 - ActiveX DLL 2.6.1.148 'CreateFile()'/ Insecure Method
CVE-2007-3493remotewindows
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz
35RISK
open
ReferênciaVexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
CVE-2008-5603webappsasp
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
My Simple Forum 3.0 - Local File Inclusion
CVE-2008-5604webappsphp
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_colorlab 1.0 - Remote File Inclusion
CVE-2007-5451webappsphp
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla!
35RISK
open
ReferênciaVexDay Proof
MyCars Automotive - Authentication Bypass
CVE-2009-2018webappsphp
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RISK
open
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3235webappsphp
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
CVE-2007-3236webappsphp
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISK
open
ReferênciaVexDay Proof
Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service)
CVE-2008-4295doshardware
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta
35RISK
open
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0467remotewindows
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RISK
open
ReferênciaVexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
CVE-2007-3237webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISK
open
ReferênciaVexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
CVE-2009-2138webappsphp
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RISK
open
ReferênciaVexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISK
open
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
CVE-2008-5626doswindows
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISK
open
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2150webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RISK
open
ReferênciaVexDay Proof
Joomla! Component flash fun! 1.0 - Remote File Inclusion
CVE-2007-4955webappsphp
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component
28RISK
open
ReferênciaVexDay Proof
Active Trade 2 - Authentication Bypass
CVE-2008-5627webappsasp
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3292webappsphp
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISK
open
ReferênciaVexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
CVE-2007-3306webappsphp
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISK
open
ReferênciaVexDay Proof
Distinct TFTP 3.10 - Writable Directory Traversal Execution (Metasploit)
CVE-2012-6664CRITICALwebappswindows
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RISK
open
ReferênciaVexDay Proof
Turnkey Arcade Script - SQL Injection (1)
CVE-2008-5629webappsphp
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
eWebquiz 8 - Authentication Bypass
CVE-2008-5631webappsasp
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Active Membership 2 - Authentication Bypass
CVE-2008-5635webappsasp
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
TxtBlog 1.0 Alpha - Local File Inclusion
CVE-2008-5639webappsphp
Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via
23RISK
open
ReferênciaVexDay Proof
patBBcode 1.0 - 'bbcodeSource.php' Remote File Inclusion
CVE-2007-5995webappsphp
PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2181webappsphp
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RISK
open
ReferênciaVexDay Proof
Opera 9.62 - 'file://' Local Heap Overflow
CVE-2008-5178localwindows
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file://
35RISK
open
ReferênciaVexDay Proof
Active Bids 3.5 - 'itemID' Blind SQL Injection
CVE-2008-5640webappsphp
SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
CVE-2008-5642webappsphp
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.