Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,226cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
ReferênciaVexDay Proof
EsFaq 2.0 - 'idcat' SQL Injection
CVE-2008-3952webappsphp
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Cosmetics Zone - 'cat_id' SQL Injection
CVE-2008-4466webappsphp
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute
23RISK
open
Referência
CVE-2017-15950
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RISK
open
Referência
CVE-2017-15956
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
23RISK
open
Referência
CVE-2009-3117
SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Shahrood - Blind SQL Injection
CVE-2008-5003webappsphp
SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote File Inclusion / SQL Injection
CVE-2008-5333webappsphp
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mydyngallery 1.4.2 - SQL Injection
CVE-2008-5957webappsphp
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers t
23RISK
open
Referência
CVE-2009-4933
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
CVE-2008-5641webappsphp
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
eDNews 2.0 - SQL Injection
CVE-2008-5820webappsphp
SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Ocean12 Membership Manager Pro - Authentication Bypass
CVE-2008-6390webappsphp
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection
CVE-2008-6989webappsphp
SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
CVE-2006-6203webappsphp
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RISK
open
Referência
CVE-2008-5638
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2023-28285
Microsoft Office Remote Code Execution Vulnerability
41RISK
open
ReferênciaVexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0839webappsphp
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
PHPhotoalbum 0.5 - Multiple SQL Injections
CVE-2008-2501webappsphp
Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2017-16928
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RISK
open
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RISK
open
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RISK
open
ReferênciaVexDay Proof
plx Ad Trader 3.2 - 'adid' SQL Injection
CVE-2008-3025webappsphp
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2009-4617
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attacker
23RISK
open
Referência
CVE-2017-15959
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-200
23RISK
open
Referência
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISK
open
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISK
open
ReferênciaVexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
CVE-2008-3352webappsphp
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
CVE-2008-3366webappsphp
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3720webappsphp
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RISK
open
previouspage 431 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.