Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Serv-U FTP Server 7.3 - (Authenticated) Remote FTP File Replacement
CVE-2008-4501remotewindows
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote auth
28RISK
open
ReferênciaVexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
CVE-2008-6394webappsphp
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Oreon 1.4 / Centreon 1.4.1 - Multiple Remote File Inclusion Vulnerabilities
CVE-2007-6485webappsphp
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute a
28RISK
open
ReferênciaVexDay Proof
PowerNews 2.5.6 - Local File Inclusion
CVE-2008-0742webappsphp
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_gallery - SQL Injection
CVE-2008-0746webappsphp
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion
CVE-2008-6410webappsphp
Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to inclu
23RISK
open
ReferênciaVexDay Proof
Joomla! / Mambo Component SWmenu 4.0 - Remote File Inclusion
CVE-2007-1699webappsphp
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Ma
28RISK
open
ReferênciaVexDay Proof
Fastpublish CMS 1.9999 - config[fsBase] Remote File Inclusion
CVE-2007-6325webappsphp
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attacke
28RISK
open
ReferênciaVexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
CVE-2008-0747doswindows
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
CVE-2008-6411webappsphp
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open
ReferênciaVexDay Proof
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
CVE-2008-6414webappsphp
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
CVE-2006-4075webappsphp
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RISK
open
ReferênciaVexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
CVE-2008-4453remotewindows
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RISK
open
ReferênciaVexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
CVE-2008-6419webappsphp
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6420webappsphp
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RISK
open
ReferênciaVexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
CVE-2007-2200webappsphp
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RISK
open
ReferênciaVexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
CVE-2007-5019dosmultiple
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
CVE-2008-0352doslinux
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISK
open
ReferênciaVexDay Proof
sflog! 0.96 - Remote File Disclosure
CVE-2008-0703webappsphp
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RISK
open
ReferênciaVexDay Proof
BloofoxCMS 0.3.4 - 'lang' Local File Inclusion
CVE-2008-5748webappsphp
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to rea
28RISK
open
ReferênciaVexDay Proof
ComicShout 2.8 - 'news_id' SQL Injection
CVE-2008-6425webappsphp
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Joomla! Component NeoGallery 1.1 - SQL Injection
CVE-2008-0752webappsphp
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
CVE-2008-6427webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RISK
open
ReferênciaVexDay Proof
VUPlayer 2.49 - '.pls' Universal Buffer Overflow
CVE-2009-0182localwindows
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
ReferênciaVexDay Proof
AIMP 2.51 build 330 - ID3v1/ID3v2 Tag Remote Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1944doswindows
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file wit
28RISK
open
ReferênciaVexDay Proof
HiveMaker Professional 1.0.2 - 'cid' SQL Injection
CVE-2008-6427webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RISK
open
ReferênciaVexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
CVE-2008-1110doslinux
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.1
28RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open
ReferênciaVexDay Proof
SolidState 0.4 - Multiple Remote File Inclusions
CVE-2006-5020webappsphp
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.