Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open
Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open
ReferênciaVexDay Proof
Post Affiliate Pro 3 - 'umprof_status' Blind SQL Injection
CVE-2008-5630webappsphp
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute
23RISK
open
Referência
CVE-2017-17870
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open
ReferênciaVexDay Proof
Active Time Billing 3.2 - Authentication Bypass
CVE-2008-5632webappsphp
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Lito Lite CMS - 'cid' SQL Injection
CVE-2008-5636webappsphp
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
CVE-2008-5642webappsphp
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RISK
open
ReferênciaVexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
CVE-2008-5651webappsphp
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote at
23RISK
open
Referência
CVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISK
open
Referência
CVE-2026-9439
Edimax BR-6675nD stainfo command injection
33RISK
open
Referência
CVE-2026-9438
yashpokharna2555 StudentManagementSystem courseDel.php resource injection
33RISK
open
ReferênciaVexDay Proof
Kwalbum 2.0.2 - Arbitrary File Upload
CVE-2008-5677webappsphp
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root,
23RISK
open
ReferênciaVexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
CVE-2008-5706remotelinux
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISK
open
ReferênciaVexDay Proof
StormBoard 1.0.1 - SQL Injection
CVE-2008-5726webappsphp
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISK
open
Referência
CVE-2017-18078
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RISK
open
Referência
CVE-2010-4982
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attacker
23RISK
open
ReferênciaVexDay Proof
ASPired2Quote - Remote Database Disclosure
CVE-2008-5885webappsasp
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allow
23RISK
open
ReferênciaVexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_registration_detailed 4.1 - Remote File Inclusion
CVE-2006-5254webappsphp
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (
23RISK
open
ReferênciaVexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5888webappsasp
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RISK
open
ReferênciaVexDay Proof
4Images 1.7.x - 'search.php' SQL Injection
CVE-2006-5236webappsphp
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche Directory - Database Disclosure
CVE-2008-5898webappsasp
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISK
open
Referência
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RISK
open
ReferênciaVexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CVE-2008-5899webappsasp
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
ReferênciaVexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
CVE-2006-5256webappsphp
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche Articles - Database Disclosure
CVE-2008-5900webappsasp
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2018-25324
Simple Fields 0.2-0.3.5 Local File Inclusion via wp_abspath
33RISK
open
previouspage 424 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.