Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
ReferênciaVexDay Proof
PollMentor 2.0 - 'pollmentorres.asp?id' SQL Injection
CVE-2007-0984webappsasp
SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHPCC 4.2 Beta - 'nickpage.php?npid' SQL Injection
CVE-2007-0985webappsphp
SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
CVE-2007-1105webappsphp
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RISK
open
Referência
CVE-2007-1107
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.3.x - Blind SQL Injection
CVE-2007-1107webappsphp
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Sinapis Forum 2.2 - 'sinapis.php?fuss' Remote File Inclusion
CVE-2007-1131webappsphp
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
CVE-2007-1163webappsphp
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Plan 9 Kernel - 'devenv.c OTRUNC/pwrite' Local Privilege Escalation
CVE-2007-1189localplan9
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite
23RISK
open
ReferênciaVexDay Proof
Admin Phorum 3.3.1a - 'del.php?include_path' Remote File Inclusion
CVE-2007-1219webappsphp
PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
CVE-2007-1225remotewindows
The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in
23RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
ReferênciaVexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
Referência
CVE-2012-1921
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Module Arcade 1.0 - 'cid' SQL Injection
CVE-2007-1978webappsphp
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arb
23RISK
open
Referência
CVE-2021-43798
CVE-2021-43798HIGHunder attack
Grafana path traversal
100RISK
open
ReferênciaVexDay Proof
XOOPS Module PopnupBlog 2.52 - 'postid' Blind SQL Injection
CVE-2007-1979webappsphp
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Module topliste 1.0 - 'cid' SQL Injection
CVE-2007-1980webappsphp
SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
AROUNDMe 0.7.7 - Multiple Remote File Inclusions
CVE-2007-1986webappsphp
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2012-1979
Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticate
23RISK
open
ReferênciaVexDay Proof
Weatimages 1.7.1 - ini[langpack] Remote File Inclusion
CVE-2007-1999webappsphp
PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, al
23RISK
open
Referência
CVE-2012-1979
Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticate
23RISK
open
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2003webappsphp
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check
23RISK
open
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2004webappsphp
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2006webappsphp
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2008webappsphp
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitra
23RISK
open
Referência
CVE-2015-2080
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat
60RISK
open
Referência
CVE-2012-2156
Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbi
23RISK
open
Referência
CVE-2009-2276
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote atta
23RISK
open
Referência
CVE-2023-5222
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISK
open
previouspage 440 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.